nerdexam
EC-Council

112-52 · Question #134

Which activity is outside the scope of an ethical hacker?

The correct answer is D. Launching a DDoS attack to test system resilience. Launching a DDoS attack (D) falls outside ethical hacking scope because it causes real, uncontrolled harm to systems and third parties - it's a destructive attack, not a controlled assessment technique. Ethical hackers operate under strict rules of engagement that prohibit…

Ethical Hacking Fundamentals

Question

Which activity is outside the scope of an ethical hacker?

Options

  • AIdentifying vulnerabilities in a client's systems
  • BExploiting vulnerabilities without intent to harm
  • CInforming hardware and software vendors of identified vulnerabilities
  • DLaunching a DDoS attack to test system resilience

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    2% (1)
  • D
    88% (37)

Explanation

Launching a DDoS attack (D) falls outside ethical hacking scope because it causes real, uncontrolled harm to systems and third parties - it's a destructive attack, not a controlled assessment technique. Ethical hackers operate under strict rules of engagement that prohibit actions that could degrade availability or damage infrastructure beyond the agreed test boundary.

Why the distractors are wrong:

  • A is a core ethical hacking activity - finding vulnerabilities is literally the job.
  • B is also valid; ethical hackers exploit vulnerabilities in a controlled, authorized way to prove impact, but without malicious intent or lasting damage.
  • C is responsible disclosure, an ethical obligation when vulnerabilities are found in third-party products.

Memory tip: Think of the ethical hacker's golden rule - "authorized, intentional, and non-destructive." A DDoS attack fails all three: it's uncontrolled in effect, harmful by nature, and typically prohibited even in pentest contracts. If an action could take down systems for innocent third parties, it's off-limits.

Topics

#Ethical Hacking Scope#Legal Boundaries#DDoS Attacks#Responsible Disclosure

Community Discussion

No community discussion yet for this question.

Full 112-52 Practice