312-50V11 · Question #400
A certified ethical hacker (CEH) completed a penetration test of the main headquarters of a company almost two months ago, but has yet to get paid. The customer is suffering from financial problems, a
The correct answer is B. Follow proper legal procedures against the company to request payment.. An ethical hacker who has not been paid must pursue legal remedies through proper channels and must never leverage access to client systems or sensitive data as leverage for payment.
Question
A certified ethical hacker (CEH) completed a penetration test of the main headquarters of a company almost two months ago, but has yet to get paid. The customer is suffering from financial problems, and the CEH is worried that the company will go out of business and end up not paying. What actions should the CEH take?
Options
- AThreaten to publish the penetration test results if not paid.
- BFollow proper legal procedures against the company to request payment.
- CTell other customers of the financial problems with payments from this company.
- DExploit some of the vulnerabilities found on the company webserver to deface it.
How the community answered
(30 responses)- A7% (2)
- B80% (24)
- C10% (3)
- D3% (1)
Why each option
An ethical hacker who has not been paid must pursue legal remedies through proper channels and must never leverage access to client systems or sensitive data as leverage for payment.
Threatening to publish confidential penetration test results as leverage for payment is extortion and violates both legal statutes and the CEH code of ethics regarding client confidentiality.
The EC-Council Code of Ethics and general professional conduct standards require that disputes over payment be resolved through lawful means such as civil litigation, mediation, or collection agencies. This approach respects the confidentiality obligations the CEH accepted when performing the test and does not expose the CEH to criminal liability. Any other option involving the use of test findings or system access as coercion would constitute extortion or unauthorized access under laws such as the CFAA.
Disclosing a client's financial difficulties to other customers violates confidentiality obligations and could constitute defamation or tortious interference depending on jurisdiction.
Exploiting vulnerabilities discovered during an authorized engagement to deface a website constitutes unauthorized computer access and is a criminal act under laws such as the Computer Fraud and Abuse Act, regardless of payment disputes.
Concept tested: CEH professional ethics and legal dispute resolution
Source: https://www.eccouncil.org/code-of-ethics/
Topics
Community Discussion
No community discussion yet for this question.