ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 455 - CAS-004 discussion

Report
Export

A junior security researcher has identified a buffer overflow vulnerability leading to remote code execution in a former employer's software. The security researcher asks for the manager's advice on the vulnerability submission process. Which of the following is the best advice the current manager can provide the security researcher?

A.
Collect proof that the exploit works in order to expedite the process.
Answers
A.
Collect proof that the exploit works in order to expedite the process.
B.
Publish proof-of-concept exploit code on a personal blog.
Answers
B.
Publish proof-of-concept exploit code on a personal blog.
C.
Recommend legal consultation about the process.
Answers
C.
Recommend legal consultation about the process.
D.
Visit a bug bounty website for the latest information.
Answers
D.
Visit a bug bounty website for the latest information.
Suggested answer: C

Explanation:

When a security researcher identifies a vulnerability, especially one involving remote code execution, they must navigate a process that protects them legally and ethically. The best advice here is to consult with legal professionals to understand any liabilities, such as potential violations of non-disclosure agreements (NDAs) or intellectual property concerns. Legal consultation ensures that the researcher follows responsible disclosure practices and avoids legal repercussions, which aligns with CASP+ guidance on managing vulnerabilities and the responsible handling of sensitive security information. CompTIA CASP+ emphasizes the importance of adhering to legal and regulatory frameworks when reporting vulnerabilities, especially when dealing with former employers or clients.

CASP+ CAS-004 Exam Objectives: Domain 1.0 -- Risk Management (Responsible Disclosure, Legal Concerns)

CompTIA CASP+ Study Guide: Handling Vulnerabilities and Legal Considerations

asked 02/10/2024
Cyrom Meryll Santos
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first