nerdexam
EC-Council

312-50V12 · Question #159

An organization suspects a persistent threat from a cybercriminal. They hire an ethical hacker, John, to evaluate their system security. John identifies several vulnerabilities and advises the organiz

The correct answer is B. Both the organization and John share responsibility because they did not adequately manage the. An ethical hacker identified multiple vulnerabilities, but due to limited resources, the organization only fixed the most severe one. A subsequent data breach exploited a different, unpatched vulnerability.

Submitted by olafpl· Mar 4, 2026Information Security and Ethical Hacking Overview

Question

An organization suspects a persistent threat from a cybercriminal. They hire an ethical hacker, John, to evaluate their system security. John identifies several vulnerabilities and advises the organization on preventive measures. However, the organization has limited resources and opts to fix only the most severe vulnerability. Subsequently, a data breach occurs exploiting a different vulnerability. Which of the following statements best describes this scenario?

Options

  • AThe organization is at fault because it did not fix all identified vulnerabilities.
  • BBoth the organization and John share responsibility because they did not adequately manage the
  • CJohn is at fault because he did not emphasize the necessity of patching all vulnerabilities.
  • DThe organization is not at fault because they used their resources as per their understanding.

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    72% (13)
  • C
    6% (1)
  • D
    17% (3)

Why each option

An ethical hacker identified multiple vulnerabilities, but due to limited resources, the organization only fixed the most severe one. A subsequent data breach exploited a different, unpatched vulnerability.

AThe organization is at fault because it did not fix all identified vulnerabilities.

While the organization made the final decision to not fix all vulnerabilities, this statement places all blame on them, overlooking the ethical hacker's role in risk communication and prioritization.

BBoth the organization and John share responsibility because they did not adequately manage theCorrect

Both the organization and John share responsibility because the organization accepted the risk of unpatched vulnerabilities due to resource constraints, and John, as the security advisor, should have ensured the residual risks were clearly communicated and understood for proper risk management.

CJohn is at fault because he did not emphasize the necessity of patching all vulnerabilities.
DThe organization is not at fault because they used their resources as per their understanding.

Concept tested: Shared responsibility in vulnerability and risk management

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility

Topics

#ethical hacking#vulnerability management#risk assessment#organizational responsibility

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice