312-50V11 · Question #401
Which initial procedure should an ethical hacker perform after being brought into an organization?
The correct answer is C. Sign a formal contract with non-disclosure.. Before any security testing begins, an ethical hacker must establish legal authorization through a formal contract and non-disclosure agreement to protect both parties.
Question
Which initial procedure should an ethical hacker perform after being brought into an organization?
Options
- ABegin security testing.
- BTurn over deliverables.
- CSign a formal contract with non-disclosure.
- DAssess what the organization is trying to protect.
How the community answered
(33 responses)- A3% (1)
- B3% (1)
- C88% (29)
- D6% (2)
Why each option
Before any security testing begins, an ethical hacker must establish legal authorization through a formal contract and non-disclosure agreement to protect both parties.
Beginning security testing without a signed contract is unauthorized access, which is illegal regardless of intent.
Delivering deliverables is the final phase of an engagement, not the initial step.
Signing a formal contract with a non-disclosure agreement is the mandatory first step because it legally authorizes the engagement, defines the scope, and protects both the hacker and the organization. Without this legal foundation, any subsequent testing would be unauthorized and potentially criminal. The contract establishes the rules of engagement before any assessment activity begins.
Assessing what the organization wants to protect is a scoping activity that occurs after the legal contract is in place, not before.
Concept tested: Ethical hacking engagement authorization and legal prerequisites
Source: https://www.eccouncil.org/train-certify/certified-ethical-hacker-ceh/
Topics
Community Discussion
No community discussion yet for this question.