ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 38 - PT0-002 discussion

Report
Export

A penetration tester who is doing a security assessment discovers that a critical vulnerability is being actively exploited by cybercriminals. Which of the following should the tester do NEXT?

A.
Reach out to the primary point of contact
Answers
A.
Reach out to the primary point of contact
B.
Try to take down the attackers
Answers
B.
Try to take down the attackers
C.
Call law enforcement officials immediately
Answers
C.
Call law enforcement officials immediately
D.
Collect the proper evidence and add to the final report
Answers
D.
Collect the proper evidence and add to the final report
Suggested answer: A

Explanation:

The penetration tester should reach out to the primary point of contact as soon as possible to inform them of the critical vulnerability and the active exploitation by cybercriminals. This is the most responsible and ethical course of action, as it allows the client to take immediate steps to mitigate the risk and protect their assets. The other options are not appropriate or effective in this situation.

Trying to take down the attackers would be illegal and dangerous, as it may escalate the conflict or cause collateral damage. Calling law enforcement officials immediately would be premature and unnecessary, as it may involve disclosing confidential information or violating the scope of the engagement. Collecting the proper evidence and adding to the final report would be too slow and passive, as it would delay the notification and remediation of the vulnerability.

asked 02/10/2024
Michel van Klaveren
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first