When planning a penetration test, why is it important to determine if the assets are hosted on a third-party cloud service?
Because cloud assets are immune to traditional testing methods.
Cloud environments are always out of scope for penetration tests to avoid complexity.
To ensure tests comply with both the customer's agreements and the cloud service provider's terms of service.
To focus testing efforts on physical hardware as cloud services are inherently secure.