nerdexam
EC-Council

312-50V11 · Question #399

An ethical hacker for a large security research firm performs penetration tests, vulnerability tests, and risk assessments. A friend recently started a company and asks the hacker to perform a penetra

The correct answer is B. Ask the employer for authorization to perform the work outside the company.. Before performing any security work outside of their employer, an ethical hacker must obtain explicit authorization from their employer to avoid conflicts of interest or violations of employment agreements.

Information Security and Ethical Hacking Fundamentals

Question

An ethical hacker for a large security research firm performs penetration tests, vulnerability tests, and risk assessments. A friend recently started a company and asks the hacker to perform a penetration test and vulnerability assessment of the new company as a favor. What should the hacker's next step be before starting work on this job?

Options

  • AStart by foot printing the network and mapping out a plan of attack.
  • BAsk the employer for authorization to perform the work outside the company.
  • CBegin the reconnaissance phase with passive information gathering and then move into active
  • DUse social engineering techniques on the friend's employees to help identify areas that may be

How the community answered

(39 responses)
  • B
    92% (36)
  • C
    5% (2)
  • D
    3% (1)

Why each option

Before performing any security work outside of their employer, an ethical hacker must obtain explicit authorization from their employer to avoid conflicts of interest or violations of employment agreements.

AStart by foot printing the network and mapping out a plan of attack.

Beginning footprinting or any active network mapping before obtaining proper authorization constitutes unauthorized access, which is illegal regardless of personal relationships.

BAsk the employer for authorization to perform the work outside the company.Correct

Most employment contracts for security professionals contain clauses covering outside work, conflict of interest, and use of employer-associated skills or resources. Performing a penetration test for an outside party without authorization could violate that agreement, expose the employer to liability, and breach professional ethics codes. Seeking employer authorization first ensures the hacker operates within legal and contractual boundaries before any technical work begins.

CBegin the reconnaissance phase with passive information gathering and then move into active

Starting any phase of reconnaissance - passive or active - without authorization is a violation of ethical hacking principles and potentially the Computer Fraud and Abuse Act.

DUse social engineering techniques on the friend's employees to help identify areas that may be

Using social engineering on the friend's employees without a signed authorization and rules of engagement is unethical and potentially unlawful, irrespective of the requester's relationship to the hacker.

Concept tested: Ethical hacker authorization and professional obligations

Source: https://www.eccouncil.org/code-of-ethics/

Topics

#ethical hacking#authorization#professional ethics#engagement rules

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice