📖 What is Scope Creep?
Scope Creep refers to the uncontrolled expansion of a project's goals or requirements without corresponding adjustments to time, budget, or resources. In penetration testing, this often occurs when a client requests additional systems or networks be tested mid-engagement without a formal contract amendment.
"Always document scope changes in writing. If you test a system not explicitly listed in the SOW, you are technically performing an unauthorized intrusion."
📚 Certification: CompTIA PenTest+ (PT0-002)
🔑 What are the Key Concepts of Scope Creep?
- ▸ The Statement of Work (SOW) serves as the legal baseline; any deviation from this document without a formal amendment constitutes scope creep.
- ▸ Testing assets outside the defined scope can lead to severe legal consequences, as it may be viewed as an unauthorized intrusion.
- ▸ Scope creep often leads to resource exhaustion, where the tester spends time on unplanned tasks, risking the quality and deadline of the report.
- ▸ A formal change control process is essential for managing scope changes, ensuring that budget, time, and resources are adjusted to match new requirements.
🎯 How does Scope Creep appear on the PT0-002 Exam?
A scenario might describe a client asking you to 'quickly check' one additional server during an engagement. You must identify this as scope creep and select the option to request a formal SOW amendment.
You may be asked how to respond when discovering a critical vulnerability on a system that was not explicitly listed in the original scope of work, focusing on communication and documentation.
❓ Frequently Asked Questions
What is the difference between scope creep and a 'pivot' during an engagement?
Pivoting is a technical maneuver where a tester moves from one compromised system to another within the agreed boundaries. Scope creep is a project management failure where the project's goals or assets expand without formal approval.
How should a penetration tester handle a client's urgent request to add a system mid-test?
The tester should inform the client that the request falls outside the current SOW. They must then initiate the formal change control process to document the addition and adjust the timeline and budget.