CompTIA PenTest+ (PT0-001) — Question 69

A client has requested an external network penetration test for compliance purposes. During discussion between the client and the penetration tester, the client expresses unwillingness to add the penetration tester's source IP addresses to the client's IPS whitelist for the duration of the test. Which of the following is the
BEST argument as to why the penetration tester's source IP addresses should be whitelisted?

Answer options

Correct answer: D

Explanation

The correct answer, D, emphasizes that the primary goal of penetration testing is to uncover security vulnerabilities rather than assess active defenses like an IPS. Options A, B, and C, while valid concerns, do not directly address the core objective of the penetration test and therefore do not provide the strongest justification for whitelisting the IP addresses.