Authorization is part of the technical answer
PenTest+ questions often contain a tempting technical action that becomes wrong because the engagement does not authorize it. Treat scope as a control boundary. If you discover a new subsidiary domain, cloud tenant, wireless network, partner system, or production dependency, stop and determine whether the written authorization actually covers it. Ownership, public accessibility, or technical reachability does not substitute for permission.
The rules of engagement should make operational risk explicit. Know the test window, approved source addresses, communication path, prohibited techniques, credential constraints, data-handling requirements, social-engineering permissions, denial-of-service limitations, emergency contacts, and stop-work conditions. When a production service becomes unstable, following the agreed escalation and safety process takes priority over completing one more test case.
Evidence handling matters from the beginning. Decide what needs to be retained, how sensitive client data will be protected, where screenshots or logs will be stored, who may access them, and how temporary artifacts will be cleaned up. A finding can be technically valid and still be professionally mishandled if evidence collection creates unnecessary exposure.