312-50V10 · Question #264
A security consultant is trying to bid on a large contract that involves penetration testing and reporting. The company accepting bids wants proof of work so the consultant prints out several audits t
The correct answer is B. The consultant may expose vulnerabilities of other companies.. Sharing audit reports from previous clients to win new business is unethical and dangerous because those reports contain sensitive vulnerability details belonging to other organizations.
Question
A security consultant is trying to bid on a large contract that involves penetration testing and reporting. The company accepting bids wants proof of work so the consultant prints out several audits that have been performed. Which of the following is likely to occur as a result?
Options
- AThe consultant will ask for money on the bid because of great work.
- BThe consultant may expose vulnerabilities of other companies.
- CThe company accepting bids will want the same type of format of testing.
- DThe company accepting bids will hire the consultant because of the great work performed.
How the community answered
(32 responses)- A6% (2)
- B75% (24)
- C3% (1)
- D16% (5)
Why each option
Sharing audit reports from previous clients to win new business is unethical and dangerous because those reports contain sensitive vulnerability details belonging to other organizations.
Asking for more money is not a consequence of sharing prior audit reports; it is unrelated to the ethical and legal risk created.
Audit and penetration test reports contain detailed findings about vulnerabilities, misconfigurations, and weaknesses specific to the client that commissioned the work. Presenting these reports to a third party - even to demonstrate competence - discloses confidential security information about those prior clients without their consent, potentially enabling exploitation of the exposed vulnerabilities.
The bidding company preferring a specific test format is a minor and unlikely outcome compared to the serious breach of client confidentiality that occurs.
Being hired is not the likely outcome; the more probable result is legal liability and reputational damage from violating client confidentiality agreements.
Concept tested: Confidentiality obligations in penetration testing engagements
Source: https://www.pentest-standard.org/index.php/Pre-engagement
Topics
Community Discussion
No community discussion yet for this question.