Concept and mechanism
An engagement starts with objectives and boundaries that can be executed and checked. Identify targets, techniques, exclusions, windows, contacts, stop conditions, and data handling. An NDA protects confidentiality but does not replace authorization to test systems. Discovering a dependency is insufficient too: an authorized name can point to shared provider infrastructure with its own rules. Scope should distinguish the contracted service from third-party resources. The team needs to know who can change the agreement and how to communicate urgent findings, limitations, and incidents during the work rather than waiting for final delivery.
Guided application
In a fictional funds project, the portal redirects to out-of-scope SaaS. Continue independent tests already authorized and record missing coverage while coordinating the dependency with the PM. Schedule pressure does not expand permission. If the plan requires stopping when p95 latency exceeds eight hundred milliseconds for two minutes, a reading of nine hundred fifty for three minutes triggers that criterion; proving causality is unnecessary before following the preventive stop rule. In the report, describe demonstrated effects using synthetic data and separate hypotheses from facts. Unauthorized reading on one endpoint does not prove extraction of the entire database. Define retesting too: fixed version, negative case, legitimate functionality, and evidence required for acceptance.
p95 of 950 ms for three minutes exceeds the agreed 800 ms for two minutes criterion.
Common pitfalls
NDA as authorization; dependency as scope; deadline as permission; hypothesis as fact; 500 errors as remediation.
Related topics: Reconnaissance and result interpretation · Discovery, coverage, and validation · Web and API flaws and remediation
Make scope, stopping, and acceptance verifiable.
Reference: Security testing and assessment · PT0-003 / PenTest+ V3; objectives 3.0; launched 2024-12-17