Scoping Questionnaire for a Penetration Test

1.Contact Info
2.Who manages your organization’s technology?
3.Why are you requesting a penetration test?
4.What would you like us to test? - Select all that apply
5.What type of information or business process is most important to protect?
A. Public Internet-Facing Systems
6.Approximately how many public-facing systems need to be tested?
7.Can you or your IT provider send us the public IP addresses or domain names?
B. Internal Network and Company Devices
8.Approximately how large is the environment?
C. Website, Portal, or Web Application
9.How many websites or applications need to be tested?
10.Does the application have different user types, such as customer, employee, manager, or administrator?
11.Please provide the URL(s), if available
API or Software Integration
12.Approximately how many API endpoints or integrations need to be tested?
13.Is technical documentation available, such as Swagger/OpenAPI or a Postman collection?
E. Cloud Environment
14.Which cloud services are in scope? Select all that apply.
15.What do you mainly want assessed?
F. Employee Phishing Awareness
16.Approximately how many employees should receive the simulation?
Timing and Budget
17.When would you like testing to begin?(Required.)
18.Do you have an approved or expected budget range?(Required.)