nerdexam
EC-Council

312-50V10 · Question #264

A security consultant is trying to bid on a large contract that involves penetration testing and reporting. The company accepting bids wants proof of work so the consultant prints out several audits t

The correct answer is B. The consultant may expose vulnerabilities of other companies.. Sharing audit reports from previous clients to win new business is unethical and dangerous because those reports contain sensitive vulnerability details belonging to other organizations.

Information Security and Ethical Hacking Fundamentals

Question

A security consultant is trying to bid on a large contract that involves penetration testing and reporting. The company accepting bids wants proof of work so the consultant prints out several audits that have been performed. Which of the following is likely to occur as a result?

Options

  • AThe consultant will ask for money on the bid because of great work.
  • BThe consultant may expose vulnerabilities of other companies.
  • CThe company accepting bids will want the same type of format of testing.
  • DThe company accepting bids will hire the consultant because of the great work performed.

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    75% (24)
  • C
    3% (1)
  • D
    16% (5)

Why each option

Sharing audit reports from previous clients to win new business is unethical and dangerous because those reports contain sensitive vulnerability details belonging to other organizations.

AThe consultant will ask for money on the bid because of great work.

Asking for more money is not a consequence of sharing prior audit reports; it is unrelated to the ethical and legal risk created.

BThe consultant may expose vulnerabilities of other companies.Correct

Audit and penetration test reports contain detailed findings about vulnerabilities, misconfigurations, and weaknesses specific to the client that commissioned the work. Presenting these reports to a third party - even to demonstrate competence - discloses confidential security information about those prior clients without their consent, potentially enabling exploitation of the exposed vulnerabilities.

CThe company accepting bids will want the same type of format of testing.

The bidding company preferring a specific test format is a minor and unlikely outcome compared to the serious breach of client confidentiality that occurs.

DThe company accepting bids will hire the consultant because of the great work performed.

Being hired is not the likely outcome; the more probable result is legal liability and reputational damage from violating client confidentiality agreements.

Concept tested: Confidentiality obligations in penetration testing engagements

Source: https://www.pentest-standard.org/index.php/Pre-engagement

Topics

#ethical hacking#confidentiality#professional ethics#penetration testing

Community Discussion

No community discussion yet for this question.

Full 312-50V10 Practice