nerdexam
EC-Council

112-52 · Question #119

Ethical hackers should follow which important guideline?

The correct answer is B. Report all findings to the appropriate stakeholders. Reporting all findings to appropriate stakeholders (B) is the cornerstone of ethical hacking because the entire purpose of authorized penetration testing is to help organizations understand and remediate their vulnerabilities - value that only exists if findings are…

Ethical Hacking Fundamentals

Question

Ethical hackers should follow which important guideline?

Options

  • AConduct testing without prior authorization
  • BReport all findings to the appropriate stakeholders
  • CShare the findings publicly to help others learn
  • DKeep the discovered vulnerabilities secret

How the community answered

(49 responses)
  • A
    6% (3)
  • B
    88% (43)
  • C
    4% (2)
  • D
    2% (1)

Explanation

Reporting all findings to appropriate stakeholders (B) is the cornerstone of ethical hacking because the entire purpose of authorized penetration testing is to help organizations understand and remediate their vulnerabilities - value that only exists if findings are communicated. Option A violates the most fundamental rule of ethical hacking: explicit, written authorization must precede any testing, without which the activity is simply illegal hacking. Option C is wrong because publicly disclosing vulnerabilities without the organization's consent (responsible disclosure) can expose users to harm and breaches trust with the client. Option D is the opposite of ethical - keeping vulnerabilities secret defeats the purpose of the engagement and could constitute negligence or even complicity if those vulnerabilities are later exploited.

Memory tip: Think of ethical hackers as "hired doctors" - they need consent before examining you (authorization), and they must report the diagnosis back to you (stakeholder reporting), not post your medical records online (no public disclosure) or hide what they found (no secrecy).

Topics

#Ethical principles#Vulnerability disclosure#Professional responsibility#Stakeholder communication

Community Discussion

No community discussion yet for this question.

Full 112-52 Practice