Scoping questions / Penetration testing

AI and LLM penetration test scoping questions

The questions asked when scoping an AI or LLM penetration test, and why each one matters. Answer them online or in a fillable PDF.

11 questions · Fillable PDF · No email required to download

These are the questions a SilentGrid consultant asks when scoping an AI or LLM penetration test. Answering them first makes the call shorter and the quote more accurate.

"Not sure" is a fine answer. Working out the unknowns is part of what the scoping call is for.

Questions marked Sizing help us prepare an accurate quote.

Before any test

  1. Why we ask: the reason sets the depth and report format, and the date fixes the testing window and any retest.

  2. Why we ask: production needs tighter limits on load, data and timing. A test copy allows more thorough techniques.

  3. Why we ask: the schedule is built around them.

  4. Why we ask: retesting is agreed at scoping, so it is scheduled and priced from the start.

AI and LLM systems

  1. Sizing

    Why we ask: each has a different attack surface and test plan.

  2. Why we ask: prompt injection is only as serious as the access behind it.

  3. Why we ask: tool access turns a successful injection into an unauthorised action.

  4. Why we ask: indirect prompt injection arrives through content the model reads.

  5. Why we ask: self-hosted and fine-tuned models add model theft and data poisoning to the scope.

  6. Why we ask: guardrails are tested against those specific rules.

  7. Sizing

    Why we ask: testing sends a large number of prompts, so limits and costs need agreeing first.

Send your answers

Your answers go to the consultant who will run the scoping call. Leave out credentials, internal addresses and other sensitive detail: general descriptions are enough.

Unanswered questions are fine; the call covers them. Handled under the privacy policy. The form is protected by Cloudflare Turnstile, which sets no cookies (Cloudflare privacy policy).