Violet Bridge Security ← Back to Site
Offensive Security · Engagement Brief

Penetration Testing Scoping

Complete the activities applicable to your engagement. Approximate answers are preferred over blank fields — our team will refine details during scoping discussions.

Pre-filled from your service request. Relevant activities have been selected based on the services you chose. Review the activity table below and adjust if needed.
Auto-saving your progress locally
👤
Contact & Reference
Who should we coordinate with for this engagement?
📋
Included Activities
Mark which service areas apply to your engagement scope
IDService AreaIncluded
AGeneral Environment & Defensive Controls
BExternal Network Penetration Testing
CInternal Network Penetration Testing
DWeb Application Penetration Testing
EMobile Application Penetration Testing
FAPI Penetration Testing
GSocial Engineering Assessment
HDesktop Application Assessment
ISecurity Assessment & Consultation
JCompliance & Reporting
Activity A

General Environment & Defensive Controls

These questions help us understand your infrastructure at a high level and plan testing around your existing security stack.

On-premises · Cloud (AWS, Azure, GCP) · Hybrid · Multi-cloud

0/2000

Windows Server versions · Linux distributions · macOS

0/2000

Firewalls / WAF · IDS / IPS · EDR / Antivirus · SIEM · DDoS protection

0/2000

Production-critical systems · Third-party hosted services · Specific IP ranges

0/2000

Change advisory board · Advance notification requirements · Maintenance windows

0/2000
Activity B

External Network Penetration Testing

These questions help us size the external assessment and understand what's exposed to the internet.

Single IPs · CIDR ranges · If unsure, we can help identify these

0/2000

Primary domains · Subdomains · Any recently acquired domains

0/2000

Web apps · Email servers · VPN endpoints · APIs · FTP/SSH · DNS

0/2000

Cloudflare · Akamai · AWS CloudFront · Third-party SaaS

0/2000

Load-balanced systems · Rate-limited services · Systems shared with other tenants

0/2000
Activity C

Internal Network Penetration Testing

This helps us understand the size and complexity of your internal network so we can scope the right level of effort.

Best estimate during business hours · Desktops, laptops, servers, network devices, IoT

0/2000

Number of segments · Any that should be excluded

0/2000

Black box (no credentials) · Gray box (limited credentials) · White box (admin credentials)

0/2000

ACL testing · VLAN hopping · Cardholder Data Environment (CDE) segmentation

0/2000

VPN · On-site with a drop box · Remote access tool · Physical presence required

0/2000
0/1000

Single domain · Multi-domain / forest · Azure AD / Entra ID · LDAP

0/2000
Activity D

Web Application Penetration Testing

We scope web app testing by application count, complexity, and role structure. These details let us estimate effort accurately.

Include any that share authentication or backend systems

0/1000

Simple brochure site · E-commerce platform · Complex enterprise application · Customer portal

0/2000

Username / password · OAuth / SAML / SSO · Multi-factor authentication · API keys

0/2000

Unauthenticated · Regular user · Manager / Moderator · Administrator · Will you provide test credentials for each?

0/2000

If staging, is it an accurate representation of production? · Any differences in configuration or data?

0/2000

Programming languages / frameworks · Web server · Database · Third-party integrations

0/2000
Activity E

Mobile Application Penetration Testing

Mobile app testing varies significantly by platform and architecture. These details help us plan the right approach.

iOS · Android · Cross-platform (React Native, Flutter, etc.)

0/1000
0/500
0/2000
0/1000
0/1000

REST APIs · GraphQL · WebSockets · Third-party SDKs

0/2000

Payment data · PII · Health information · Location data

0/2000
Activity F

API Penetration Testing

API scope depends on endpoint count, complexity, and documentation availability.

0/500

Rough count is fine · Read-only vs. read/write split if known

0/1000

REST · SOAP · GraphQL · gRPC · WebSocket

0/1000

API keys · OAuth 2.0 / JWT · Mutual TLS · Role-based access

0/2000

OpenAPI / Swagger specs · Postman collections · Developer docs

0/1000
0/1000
Activity G

Social Engineering Assessment

Social engineering scope depends on the type of exercise, target audience, and organizational context.

Email phishing · Voice phishing (vishing) · SMS phishing (smishing) · Physical security testing · Pretexting / impersonation

0/2000

Total headcount in scope · Specific departments or roles

0/1000

Executives · Recent hires · Specific departments

0/1000

Type of training · When it was last conducted · Completion rates if known

0/2000

Phish alert button · Helpdesk reporting · Incident response procedures

0/2000

Baseline measurement · Training validation · Compliance requirement · Red team realism

0/2000
Activity H

Desktop Application Assessment

Desktop app testing requires specific logistics around software access and platform support.

0/500
0/1000

Windows · macOS · Linux · Specific OS versions

0/1000
0/1000
0/1000
0/1000
Activity I

Security Assessment & Consultation

Assessment engagements involve document review and stakeholder interviews. These details help us plan the timeline.

Policies & procedures · Technical controls · Awareness & training · Incident response · Vendor management · Physical security

0/2000

Areas where you feel least confident · Recent incidents or near-misses

0/2000
0/1000
0/1000
0/2000
0/2000
Activity J

Compliance & Reporting Requirements

Understanding your reporting needs upfront ensures deliverables meet stakeholder expectations.

PCI DSS · HIPAA · SOX · ISO 27001 · NIST CSF · FedRAMP · FISMA · Industry-specific

0/2000
0/1000

Technical team · Executive leadership · Board of directors · Auditors · Regulators

0/1000
0/1000
0/1000

Preliminary findings deadline · Final report delivery date · Formal presentation or review meeting needed?

0/2000
0/2000

Responses are transmitted securely. All scoping information is treated as confidential. See our Privacy Notice.

Scoping Brief Submitted

Thank you. Your scoping information has been received and your consultant will follow up within one business day to discuss scope, timeline, and next steps.

← Return to Homepage