nerdexam
Cisco

300-220 · Question #117

Which of the following indicates an authorized assessment rather than an attack?

The correct answer is C. A detailed report provided at the end of the activities. Option C is correct because a formal deliverable report is the defining artifact of an authorized penetration test - it documents findings, evidence, and remediation recommendations for the client who commissioned the work. Attackers have no reason or obligation to report back…

Threat Hunting Fundamentals

Question

Which of the following indicates an authorized assessment rather than an attack?

Options

  • AUse of a known exploit tool
  • BPresence of a payload that encrypts data for ransom
  • CA detailed report provided at the end of the activities
  • DQuick escalation of privileges upon entry

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    92% (24)

Explanation

Option C is correct because a formal deliverable report is the defining artifact of an authorized penetration test - it documents findings, evidence, and remediation recommendations for the client who commissioned the work. Attackers have no reason or obligation to report back to their victims.

Why the distractors fail:

  • A (exploit tools): Both attackers and authorized pen testers use the same tools (e.g., Metasploit, Mimikatz) - tool use alone cannot distinguish intent or authorization.
  • B (ransomware payload): Encrypting data for ransom is a criminal act; no legitimate engagement scope permits deploying live ransomware against a client.
  • D (quick privilege escalation): Speed of escalation reflects skill, not authorization - malicious actors and pen testers both escalate privileges as fast as possible once inside.

Memory tip: Think "authorized = accountable." A real assessment leaves a paper trail - scope documents going in, a report coming out. If there's no report, there's no contract; if there's no contract, it's an attack.

Topics

#Authorized Assessment#Penetration Testing#Assessment Documentation#Security Testing

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice