nerdexam
EC-Council

312-50V13 · Question #419

John, a security analyst working for an organization, found a critical vulnerability on the organization's LAN that allows him to view financial and personal information about the rest of the…

The correct answer is D. Gray hat. John's actions of discovering a vulnerability, then accessing sensitive information out of curiosity and considering future misuse before reporting, align with the definition of a gray hat hacker.

Submitted by noor.lb· Mar 6, 2026Introduction to Ethical Hacking

Question

John, a security analyst working for an organization, found a critical vulnerability on the organization's LAN that allows him to view financial and personal information about the rest of the employees. Before reporting the vulnerability, he examines the information shown by the vulnerability for two days without disclosing any information to third parties or other internal employees. He does so out of curiosity about the other employees and may take advantage of this information later. What would John be considered as?

Options

  • ACybercriminal
  • BBlack hat
  • CWhite hat
  • DGray hat

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    3% (1)
  • D
    87% (33)

Why each option

John's actions of discovering a vulnerability, then accessing sensitive information out of curiosity and considering future misuse before reporting, align with the definition of a gray hat hacker.

ACybercriminal

A cybercriminal typically refers to someone who commits crimes over the internet with malicious intent; while John's actions are unethical, 'gray hat' more precisely describes his nuanced role.

BBlack hat

A black hat hacker exploits vulnerabilities for personal gain or malicious purposes, often causing damage, but John's consideration of reporting (even delayed) and initial 'curiosity' indicates a gray area.

CWhite hat

A white hat hacker would discover the vulnerability and immediately report it through proper channels without exploiting it or accessing sensitive data for personal curiosity.

DGray hatCorrect

A gray hat hacker identifies vulnerabilities without permission, but unlike a black hat, they may not have malicious intent to cause direct harm, often seeking to disclose the flaw. However, their actions of accessing data without authorization and considering personal gain (curiosity, potentially taking advantage) place them outside of purely ethical "white hat" behavior.

Concept tested: Hacker classifications (gray hat)

Topics

#ethical hacking#hacker types#gray hat

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice