312-50V9 · Question #176
An ethical hacker for a large security research firm performs penetration tests, vulnerability tests, and risk assessments. A friend recently started a company and asks the hacker to perform a…
The correct answer is B. Ask the employer for authorization to perform the work outside the company. An ethical hacker employed by a firm must obtain employer authorization before performing outside security work, as employment agreements commonly restrict or govern such activities.
Question
An ethical hacker for a large security research firm performs penetration tests, vulnerability tests, and risk assessments. A friend recently started a company and asks the hacker to perform a penetration test and vulnerability assessment of the new company as a favor. What should the hacker's next step be before starting work on this job?
Options
- AStart by foot printing the network and mapping out a plan of attack.
- BAsk the employer for authorization to perform the work outside the company.
- CBegin the reconnaissance phase with passive information gathering and then move into active
- DUse social engineering techniques on the friend's employees to help identify areas that may be
How the community answered
(41 responses)- A17% (7)
- B71% (29)
- C5% (2)
- D7% (3)
Why each option
An ethical hacker employed by a firm must obtain employer authorization before performing outside security work, as employment agreements commonly restrict or govern such activities.
Beginning footprinting without proper authorization constitutes unauthorized access activity, which is illegal regardless of intent.
Most employment contracts for security professionals include clauses restricting outside consulting, especially work that involves sensitive skills like penetration testing. Performing unauthorized external work could violate the contract, create liability for the employer, and breach ethical obligations. Getting explicit written authorization from the employer protects both the hacker and the firm before any engagement begins.
Starting reconnaissance - even passive - before securing authorization violates ethical hacking principles and potentially applicable computer crime laws.
Using social engineering on the friend's employees without a signed agreement and employer authorization is unethical and potentially illegal.
Concept tested: Ethical hacker employment authorization for outside engagements
Source: https://www.eccouncil.org/code-of-ethics/
Topics
Community Discussion
No community discussion yet for this question.