312-50V11 · Question #399
An ethical hacker for a large security research firm performs penetration tests, vulnerability tests, and risk assessments. A friend recently started a company and asks the hacker to perform a penetra
The correct answer is B. Ask the employer for authorization to perform the work outside the company.. Before performing any security work outside of their employer, an ethical hacker must obtain explicit authorization from their employer to avoid conflicts of interest or violations of employment agreements.
Question
An ethical hacker for a large security research firm performs penetration tests, vulnerability tests, and risk assessments. A friend recently started a company and asks the hacker to perform a penetration test and vulnerability assessment of the new company as a favor. What should the hacker's next step be before starting work on this job?
Options
- AStart by foot printing the network and mapping out a plan of attack.
- BAsk the employer for authorization to perform the work outside the company.
- CBegin the reconnaissance phase with passive information gathering and then move into active
- DUse social engineering techniques on the friend's employees to help identify areas that may be
How the community answered
(39 responses)- B92% (36)
- C5% (2)
- D3% (1)
Why each option
Before performing any security work outside of their employer, an ethical hacker must obtain explicit authorization from their employer to avoid conflicts of interest or violations of employment agreements.
Beginning footprinting or any active network mapping before obtaining proper authorization constitutes unauthorized access, which is illegal regardless of personal relationships.
Most employment contracts for security professionals contain clauses covering outside work, conflict of interest, and use of employer-associated skills or resources. Performing a penetration test for an outside party without authorization could violate that agreement, expose the employer to liability, and breach professional ethics codes. Seeking employer authorization first ensures the hacker operates within legal and contractual boundaries before any technical work begins.
Starting any phase of reconnaissance - passive or active - without authorization is a violation of ethical hacking principles and potentially the Computer Fraud and Abuse Act.
Using social engineering on the friend's employees without a signed authorization and rules of engagement is unethical and potentially unlawful, irrespective of the requester's relationship to the hacker.
Concept tested: Ethical hacker authorization and professional obligations
Source: https://www.eccouncil.org/code-of-ethics/
Topics
Community Discussion
No community discussion yet for this question.