ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 203 - PT0-002 discussion

Report
Export

During the scoping phase of an assessment, a client requested that any remote code exploits discovered during testing would be reported immediately so the vulnerability could be fixed as soon as possible. The penetration tester did not agree with this request, and after testing began, the tester discovered a vulnerability and gained internal access to the system. Additionally, this scenario led to a loss of confidential credit card data and a hole in the system. At the end of the test, the penetration tester willfully failed to report this information and left the vulnerability in place. A few months later, the client was breached and credit card data was stolen. After being notified about the breach, which of the following steps should the company take NEXT?

A.
Deny that the vulnerability existed
Answers
A.
Deny that the vulnerability existed
B.
Investigate the penetration tester.
Answers
B.
Investigate the penetration tester.
C.
Accept that the client was right.
Answers
C.
Accept that the client was right.
D.
Fire the penetration tester.
Answers
D.
Fire the penetration tester.
Suggested answer: B

Explanation:

The penetration tester violated the client's request and the code of ethics by not reporting the vulnerability immediately and leaving it in place. This could have contributed to the breach and the data loss. The company should investigate the penetration tester's actions and motives, and hold them accountable for any negligence or malpractice.

asked 02/10/2024
Andre van Mierlo
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first