You are pen testing a network and client side testing is within the scope. The system administrators do not want you to start testing until they have patched the systems you will be pen testing. Will waiting result in a valid pen test?
1) No, to make an accurate assessment of the risk you need to examine representative systems
2) Yes, you want to find as few vulnerabilities as possible when pen testing
3) No, patching will increase the number of false positives
4) Yes, patching will reduce the number of false positives