nerdexam
EC-Council

312-50V11 · Question #472

One of the Forbes 500 companies has been subjected to a large scale attack. You are one of the shortlisted pen testers that they may hire. During the interview with the CIO, he emphasized that he want

The correct answer is C. Explain to the CIO that you cannot eliminate all risk, but you will be able to reduce risk to. Risk can never be fully eliminated in security - it can only be identified, reduced, and managed to an acceptable level.

Information Security and Ethical Hacking Fundamentals

Question

One of the Forbes 500 companies has been subjected to a large scale attack. You are one of the shortlisted pen testers that they may hire. During the interview with the CIO, he emphasized that he wants to totally eliminate all risks. What is one of the first things you should do when hired?

Options

  • AInterview all employees in the company to rule out possible insider threats.
  • BEstablish attribution to suspected attackers.
  • CExplain to the CIO that you cannot eliminate all risk, but you will be able to reduce risk to
  • DStart the Wireshark application to start sniffing network traffic.

How the community answered

(56 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    93% (52)
  • D
    2% (1)

Why each option

Risk can never be fully eliminated in security - it can only be identified, reduced, and managed to an acceptable level.

AInterview all employees in the company to rule out possible insider threats.

Interviewing all employees to rule out insider threats is a valid activity but is not the first priority and does not address the CIO's incorrect assumption about total risk elimination.

BEstablish attribution to suspected attackers.

Establishing attribution to suspected attackers is an incident response and forensics activity, not a foundational first step in a penetration testing engagement.

CExplain to the CIO that you cannot eliminate all risk, but you will be able to reduce risk toCorrect

A fundamental principle of information security is that zero risk is unattainable; every system carries residual risk after controls are applied. A professional penetration tester must set accurate expectations with stakeholders by explaining that the engagement will identify and reduce risk to an acceptable threshold, not eliminate it entirely. Misrepresenting this could lead to false confidence and negligent security posture from the client.

DStart the Wireshark application to start sniffing network traffic.

Launching Wireshark immediately without a scoping agreement or authorization is premature and could violate legal boundaries before a formal engagement is established.

Concept tested: Risk management principles and pen tester responsibilities

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-30r1.pdf

Topics

#risk management#penetration testing scope#risk reduction#ethics

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice