312-50V11 · Question #767
Which of the following statements regarding ethical hacking is incorrect?
The correct answer is B. Ethical hackers should never use tools or methods that have the potential of exploiting. Statement B is incorrect because ethical hackers are required to use the same exploitation tools and techniques as malicious attackers in order to accurately identify and validate real-world vulnerabilities.
Question
Which of the following statements regarding ethical hacking is incorrect?
Options
- AAn organization should use ethical hackers who do not sell vendor hardware/software or other
- BEthical hackers should never use tools or methods that have the potential of exploiting
- CEthical hacking should not involve writing to or modifying the target systems.
- DTesting should be remotely performed offsite.
How the community answered
(36 responses)- A3% (1)
- B86% (31)
- C3% (1)
- D8% (3)
Why each option
Statement B is incorrect because ethical hackers are required to use the same exploitation tools and techniques as malicious attackers in order to accurately identify and validate real-world vulnerabilities.
This statement is correct - ethical hackers should remain independent and free from vendor financial relationships to avoid conflicts of interest that could bias their assessment.
Ethical hacking - also called penetration testing - is fundamentally defined by employing the same attack tools, exploits, and methods that real adversaries use; banning exploitation techniques would make it impossible to validate whether vulnerabilities are actually exploitable and would produce an incomplete security assessment. Restricting ethical hackers from using exploitation methods directly contradicts the core methodology of the discipline and the purpose of a penetration test.
This statement is correct - ethical hacking engagements are designed to be non-destructive, and writing to or permanently modifying target systems goes beyond the agreed scope of a legitimate assessment.
This statement is correct as a general guideline - performing testing remotely offsite is an accepted and common practice that simulates an external attacker and reduces physical access complications.
Concept tested: Ethical hacking principles and penetration testing methodology
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.