312-50V11 · Question #472
One of the Forbes 500 companies has been subjected to a large scale attack. You are one of the shortlisted pen testers that they may hire. During the interview with the CIO, he emphasized that he want
The correct answer is C. Explain to the CIO that you cannot eliminate all risk, but you will be able to reduce risk to. Risk can never be fully eliminated in security - it can only be identified, reduced, and managed to an acceptable level.
Question
One of the Forbes 500 companies has been subjected to a large scale attack. You are one of the shortlisted pen testers that they may hire. During the interview with the CIO, he emphasized that he wants to totally eliminate all risks. What is one of the first things you should do when hired?
Options
- AInterview all employees in the company to rule out possible insider threats.
- BEstablish attribution to suspected attackers.
- CExplain to the CIO that you cannot eliminate all risk, but you will be able to reduce risk to
- DStart the Wireshark application to start sniffing network traffic.
How the community answered
(56 responses)- A2% (1)
- B4% (2)
- C93% (52)
- D2% (1)
Why each option
Risk can never be fully eliminated in security - it can only be identified, reduced, and managed to an acceptable level.
Interviewing all employees to rule out insider threats is a valid activity but is not the first priority and does not address the CIO's incorrect assumption about total risk elimination.
Establishing attribution to suspected attackers is an incident response and forensics activity, not a foundational first step in a penetration testing engagement.
A fundamental principle of information security is that zero risk is unattainable; every system carries residual risk after controls are applied. A professional penetration tester must set accurate expectations with stakeholders by explaining that the engagement will identify and reduce risk to an acceptable threshold, not eliminate it entirely. Misrepresenting this could lead to false confidence and negligent security posture from the client.
Launching Wireshark immediately without a scoping agreement or authorization is premature and could violate legal boundaries before a formal engagement is established.
Concept tested: Risk management principles and pen tester responsibilities
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.