nerdexam
EC-Council

312-50V9 · Question #177

A certified ethical hacker (CEH) completed a penetration test of the main headquarters of a company almost two months ago, but has yet to get paid. The customer is suffering from financial problems…

The correct answer is B. Follow proper legal procedures against the company to request payment. When a client fails to pay, an ethical hacker must pursue legal remedies and must never use knowledge of vulnerabilities as leverage or retaliation.

Introduction to Ethical Hacking

Question

A certified ethical hacker (CEH) completed a penetration test of the main headquarters of a company almost two months ago, but has yet to get paid. The customer is suffering from financial problems, and the CEH is worried that the company will go out of business and end up not paying. What actions should the CEH take?

Options

  • AThreaten to publish the penetration test results if not paid.
  • BFollow proper legal procedures against the company to request payment.
  • CTell other customers of the financial problems with payments from this company.
  • DExploit some of the vulnerabilities found on the company webserver to deface it.

How the community answered

(34 responses)
  • A
    12% (4)
  • B
    79% (27)
  • C
    6% (2)
  • D
    3% (1)

Why each option

When a client fails to pay, an ethical hacker must pursue legal remedies and must never use knowledge of vulnerabilities as leverage or retaliation.

AThreaten to publish the penetration test results if not paid.

Threatening to publish penetration test results constitutes extortion or blackmail, which is a criminal offense and a direct violation of non-disclosure agreements.

BFollow proper legal procedures against the company to request payment.Correct

Following proper legal procedures - such as sending a demand letter or pursuing a civil claim - is the only ethical and lawful recourse available. Retaliatory actions using technical knowledge gained during the engagement would constitute criminal offenses and violate the CEH code of ethics. Legal channels preserve the hacker's professional standing and provide a legitimate path to recovery.

CTell other customers of the financial problems with payments from this company.

Disclosing a client's financial difficulties to third parties likely violates NDA terms and could constitute defamation or tortious interference.

DExploit some of the vulnerabilities found on the company webserver to deface it.

Exploiting vulnerabilities to deface the webserver is unauthorized computer access, a serious criminal offense under laws such as the Computer Fraud and Abuse Act.

Concept tested: Ethical hacker legal and ethical conduct post-engagement

Source: https://www.eccouncil.org/code-of-ethics/

Topics

#professional ethics#legal remedies#code of conduct#ethical hacker obligations

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice