300-220 · Question #117
Which of the following indicates an authorized assessment rather than an attack?
The correct answer is C. A detailed report provided at the end of the activities. Option C is correct because a formal deliverable report is the defining artifact of an authorized penetration test - it documents findings, evidence, and remediation recommendations for the client who commissioned the work. Attackers have no reason or obligation to report back…
Question
Which of the following indicates an authorized assessment rather than an attack?
Options
- AUse of a known exploit tool
- BPresence of a payload that encrypts data for ransom
- CA detailed report provided at the end of the activities
- DQuick escalation of privileges upon entry
How the community answered
(26 responses)- A4% (1)
- B4% (1)
- C92% (24)
Explanation
Option C is correct because a formal deliverable report is the defining artifact of an authorized penetration test - it documents findings, evidence, and remediation recommendations for the client who commissioned the work. Attackers have no reason or obligation to report back to their victims.
Why the distractors fail:
- A (exploit tools): Both attackers and authorized pen testers use the same tools (e.g., Metasploit, Mimikatz) - tool use alone cannot distinguish intent or authorization.
- B (ransomware payload): Encrypting data for ransom is a criminal act; no legitimate engagement scope permits deploying live ransomware against a client.
- D (quick privilege escalation): Speed of escalation reflects skill, not authorization - malicious actors and pen testers both escalate privileges as fast as possible once inside.
Memory tip: Think "authorized = accountable." A real assessment leaves a paper trail - scope documents going in, a report coming out. If there's no report, there's no contract; if there's no contract, it's an attack.
Topics
Community Discussion
No community discussion yet for this question.