ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 339 - PT0-002 discussion

Report
Export

A penetration tester requested, without express authorization, that a CVE number be assigned for a new vulnerability found on an internal client application. Which of the following did the penetration tester most likely breach?

A.
ROE
Answers
A.
ROE
B.
SLA
Answers
B.
SLA
C.
NDA
Answers
C.
NDA
D.
SOW
Answers
D.
SOW
Suggested answer: A

Explanation:

ROE stands for Rules of Engagement, which are the guidelines and limitations that define the scope, objectives, and methods of a penetration testing engagement. ROE should be agreed upon by both the client and the tester before the testing begins, and they should include the authorization to perform certain actions, such as requesting CVE numbers, disclosing vulnerabilities, or exploiting systems. By requesting a CVE number without express authorization, the penetration tester most likely breached the ROE and violated the client's trust and expectations.

Reference:

* The Official CompTIA PenTest+ Study Guide (Exam PT0-002), Chapter 1: Planning and Scoping Penetration Tests, page 23-24.

* CVE - CVE1

* NDA, MSA, SOW and SLA. Confidentiality agreements when you outsource QA

asked 02/10/2024
Micele Mercer
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first