Scoping questions / Penetration testing

Web app penetration test scoping questions

The questions asked when scoping a web application or API penetration test, and why each one matters. Answer them online or in a fillable PDF.

12 questions · Fillable PDF · No email required to download

These are the questions a SilentGrid consultant asks when scoping a web application or API penetration test. Answering them first makes the call shorter and the quote more accurate.

"Not sure" is a fine answer. Working out the unknowns is part of what the scoping call is for.

Questions marked Sizing help us prepare an accurate quote.

Before any test

  1. Why we ask: the reason sets the depth and report format, and the date fixes the testing window and any retest.

  2. Why we ask: production needs tighter limits on load, data and timing. A test copy allows more thorough techniques.

  3. Why we ask: the schedule is built around them.

  4. Why we ask: retesting is agreed at scoping, so it is scheduled and priced from the start.

Web applications and services

  1. Sizing

    Why we ask: the count drives effort, and the stack decides which classes of flaw are most likely.

  2. Sizing

    Why we ask: authorisation testing needs a second user at each level, so one can try to reach the other's data or functions.

  3. Why we ask: one customer reading another's data is the most serious flaw a SaaS platform can have.

  4. Sizing

    Why we ask: documented APIs can be covered completely. GraphQL needs its own test cases.

  5. Why we ask: each sign-in flow has its own known bypasses, from token handling to skipped multi-factor steps.

  6. Why we ask: business logic flaws in these workflows are what automated scanners miss.

  7. Why we ask: server-side request forgery and injection often hide in these features.

  8. Why we ask: code-assisted testing finds flaws that are invisible from outside, such as unsafe deserialisation or hard-coded secrets.

Send your answers

Your answers go to the consultant who will run the scoping call. Leave out credentials, internal addresses and other sensitive detail: general descriptions are enough.

Unanswered questions are fine; the call covers them. Handled under the privacy policy. The form is protected by Cloudflare Turnstile, which sets no cookies (Cloudflare privacy policy).