Skip to Content
Penetration Testing

Scoping Questionnaire

Tell us what you would like tested and we will follow up. It takes about two minutes. You can add more detail if you have it, but you do not need to.

Please do not include passwords, keys or other credentials in this form.

Prefer to fill out a document? Download the PDF.

Complete the PDF on your computer, then email it back to us. Or skip this and use the short online form below, which sends itself to us.

  1. Download the fillable PDF and open it in Adobe Acrobat Reader, Chrome, Edge or Preview.
  2. Fill it in and save it (File > Save).
  3. Email the saved PDF as an attachment to c@rdctd.com. Use the subject "Pen test scoping - your company name".
Download the PDF (8 pages)

About you

What would you like tested?

Select everything that applies. Not sure yet? Skip this and tell us about your goals below.

Infrastructure
Cloud
Applications
Advanced
Add more detail (optional)

Skip this and we will follow up with questions. Filling it in helps us scope and price your engagement faster.

Service details

Open only the sections for the services you selected. Estimates are fine.

Application Security Testing

Details that help us size web, mobile, API, AI and thick client testing.

Web Applications
Web application 1
Web application 2
Web application 3
Web application 4
Web application 5
AI / LLM Features (complete if applicable)
Mobile Applications
Mobile application 1
Mobile application 2
Mobile application 3
Thick Client Applications
Thick client application 1
Thick client application 2
Thick client application 3
On-Prem Infrastructure Penetration Testing

Internal and external network, wireless, attack surface and Active Directory scoping.

Environment Details

Use the location columns if your environment spans more than one site. Approximate figures are fine.

# of External Targets
# of Live External IPs
# of Internal Targets
Identity Provider
# of Physical Servers
# of VMs
# of Endpoints (end user devices, workstations)
Type of Endpoints
End-User Work Environment
# of Network Components (firewalls, routers, switches, access points, load balancers)
# of Active Directory domains (on-prem and cloud combined)
What EDR/XDR do you use? (e.g., SentinelOne, CrowdStrike)
Are there any Operational Technology (OT) assets in the in-scope IT environment?
If yes, is the OT environment segmented from IT?
Where are your servers hosted?
Wireless Testing
Attack Surface Penetration Testing
Active Directory
Cloud Infrastructure Penetration Testing

Complete only the platforms you use.

Azure Cloud Infrastructure Environment

Internal Kubernetes testing is when a kubeconfig or access to a pod is provided. External testing looks at the cluster from an outside perspective.

AWS Cloud Infrastructure Environment

Internal Kubernetes testing is when a kubeconfig or access to a pod is provided. External testing looks at the cluster from an outside perspective.

GCP Cloud Infrastructure Environment

Internal Kubernetes testing is when a kubeconfig or access to a pod is provided. External testing looks at the cluster from an outside perspective.

Assumed-Breach Penetration Testing

Starts from the premise that an attacker is already inside.

Operational Technology (OT) Penetration Testing

PLCs, HMIs and SCADA environments, planned around your operational constraints.

Asset Counts
Additional Questions
Social Engineering

Select the activities you would like included.

Red Teaming

Goal-based adversary simulation scoped around agreed starting points.

Starting Points
Purple Teaming

A collaborative exercise with your defenders to validate detections.

Physical Hardware Testing

Firmware, debug interfaces and components of a device.

Security Maturity Assessment

Reviews your policies, processes and team structure.

Terminology & definitions

If you are unsure how to count something, an estimate is fine. We will confirm details before testing begins.

Tenant / Domains. Your Microsoft Entra ID (formerly Azure Active Directory) tenant and the domains associated with it.

Subscriptions. A billing and access boundary in Azure that contains one or more resource groups.

Resource Groups. A container that holds related resources for an Azure solution.

Resources. An individual item within a resource group, such as a VM, database, or storage account.

Enterprise Applications. An application's identity within your directory (Entra ID).

Storage Accounts. An Azure storage account holds your Azure Storage data objects: blobs, files, queues, and tables.

Virtual Network (VNet). Azure's private network that connects and isolates your Azure resources (the Azure equivalent of a VPC).

Cloud — Amazon Web Services (AWS)

AWS Accounts. If the engagement involves multiple AWS accounts (not regions), include the number of accounts in scope.

AWS Console Access. The number of users or roles with access to the AWS console, regardless of access level.

EC2 (Elastic Compute Cloud). Virtual servers running in AWS. The total count helps determine the effort involved.

ECS (Elastic Container Service). AWS's container orchestration service. The number of containers or tasks in use helps determine the effort involved.

EKS (Elastic Kubernetes Service). AWS's managed Kubernetes service. Further questions about the architecture may follow.

S3 (Simple Storage Service). Object storage. Further questions may follow about which buckets are public and which are private.

Lambda. AWS's serverless compute service, which runs code without provisioning servers.

VPC (Virtual Private Cloud). A logically isolated network in AWS where your resources run. The number of VPCs helps determine network scope.

Cloud — Google Cloud (GCP)

Organizations. The top-level container for your Google Cloud resources, usually tied to your company domain.

Projects. The GCP projects involved in the engagement. Resources, billing, and permissions are organized by project.

Compute Engine. Virtual machine instances running in GCP.

GKE (Google Kubernetes Engine). Google's managed Kubernetes service. Count the clusters and approximate number of pods.

Cloud Storage Buckets. Buckets used for object storage in GCP.

Cloud Run functions / services. Serverless functions and containerized applications running on Cloud Run.

VPC (Virtual Private Cloud). Google Cloud's networking layer for Compute Engine VMs, GKE clusters, and serverless workloads.

Cloud — All Providers

Regions. The number of geographic regions where you run resources that are in scope.

Kubernetes Clusters. A set of nodes that run containerized workloads. Each cluster runs one or more pods.

Kubernetes Node Pools. A group of nodes within a cluster that share the same configuration (CPU, memory, networking, OS, maximum pods, etc.).

Internal vs. External Kubernetes Testing. Internal testing means the testing team is given a kubeconfig or access to a pod, and hardening is assessed from inside the cluster. External testing looks at the cluster from an outside perspective.

Applications

API Endpoints. The specific paths on the server that handle requests and responses. The total number helps determine the size of the application.

Dynamic Pages. Pages generated in real time from a database, with content that changes based on user input. The count helps determine the testing effort.

User Roles. The number of distinct user roles in the application. If roles are dynamic, state the number you'd like tested.

Single Page App (SPA). An application that updates a single HTML page in response to user actions, typically built with React, Angular, or Vue.

Authentication. Whether the application requires users to log in, plus any details you can share about how.

Serverless. Whether the application runs on serverless infrastructure, such as AWS Lambda or Azure Functions.

On-Prem IT

External IPs. Internet-facing IP addresses that are currently live.

Physical Servers. Bare-metal servers, which may host several VMs.

VMs. The number of virtual machines across the environment.

Endpoints. End-user devices and workstations, primarily domain-joined Windows PCs and Macs.

Network Components. Primarily switches, routers, and firewalls. Access points and phones can be noted, but count one per device type.

Active Directory Domain. A collection of objects, possibly spanning multiple domain controllers, counts as one domain. For example, acme.local is one domain; a separate acme-corp.local with no trust relationship would be a second.

PCI Segments. The number of PCI network segments (subnets) in scope.

Cardholder Data Environment (CDE). The part of a network that stores, processes, or transmits cardholder data or sensitive authentication data.

Operational Technology (OT)

PLCs / Critical Infrastructure (High Risk). Systems with high potential for harm if compromised, such as those running power generation, water treatment, or transportation networks.

Misc. OT Devices (Medium Risk). Systems such as HVAC controls, smart meters, test-environment PLCs, and backup controllers.

Misc. OT Devices (Low Risk). Non-essential monitoring devices, lab equipment, and other OT that doesn't directly affect critical processes.

OT Environments. A distinct operational site or segmented control network (e.g., a plant, facility, or production line) with its own OT assets.