nerdexam
Cisco

300-220 · Question #112

Selecting the delivery method for an attack, which aspect is least likely to be used by a legitimate penetration tester without explicit authorization?

The correct answer is B. Deploying a backdoor for later access. Deploying a backdoor (B) crosses a critical ethical and legal boundary even in authorized penetration tests - it creates persistent unauthorized access that extends beyond the agreed-upon engagement scope, introduces real risk to the target environment, and is rarely included…

Threat Modeling Techniques

Question

Selecting the delivery method for an attack, which aspect is least likely to be used by a legitimate penetration tester without explicit authorization?

Options

  • ASocial engineering employees over email
  • BDeploying a backdoor for later access
  • CPerforming vulnerability scanning
  • DTesting physical security measures

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    74% (32)
  • C
    9% (4)
  • D
    14% (6)

Explanation

Deploying a backdoor (B) crosses a critical ethical and legal boundary even in authorized penetration tests - it creates persistent unauthorized access that extends beyond the agreed-upon engagement scope, introduces real risk to the target environment, and is rarely included in a standard pen test authorization agreement without highly specific written approval.

Why the distractors are wrong:

  • (A) Social engineering via email is a standard, explicitly authorized technique in phishing simulations and red team engagements - it's routine scope.
  • (C) Vulnerability scanning is arguably the most common and baseline-authorized activity in any pen test; it's almost always in scope.
  • (D) Physical security testing (badge cloning, tailgating) is a legitimate and common red team activity when explicitly authorized in the rules of engagement.

Memory tip: Think "persistence = problem." A backdoor is the one technique that persists after the test ends, which is why it requires exceptional, explicit authorization that most standard pen test contracts don't include. All other options are time-bounded active tests; a backdoor lingers.

Topics

#penetration testing authorization#attack delivery methods#backdoor persistence#authorized vs unauthorized testing

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice