The signed rules of engagement list only IP ranges the client owns. At kickoff the client also asks you to test app.partner-crm.example, which resolves into a hosting provider's address space. What has to happen before you send traffic at that host?
- ANothing further. The client asked in writing, and that written request is the authorization.
- BGet written authorization from the hosting provider, then amend the scope document to match.
- CRestrict yourself to an unauthenticated port scan, since scanning is not covered by computer-misuse law.
- DDefer the host to the retest window and record it as a scope gap in the final report.
Show the answer
B. Get written authorization from the hosting provider, then amend the scope document to match.
A client can only authorize systems it actually controls. A host living in a third party's address space needs that provider's written sign-off first, and the scope document gets amended so the paperwork matches what you tested. Port scanning is not a legal exemption either — it is active traffic aimed at someone else's asset.