nerdexam
EC-Council

312-50V9 · Question #271

A well-intentioned researcher discovers a vulnerability on the web site of a major corporation. What should he do?

The correct answer is C. Notify the web site owner so that corrective action be taken as soon as possible to patch the. When a researcher discovers a vulnerability, responsible disclosure requires notifying the affected organization directly so they can remediate it before malicious exploitation occurs.

Introduction to Ethical Hacking

Question

A well-intentioned researcher discovers a vulnerability on the web site of a major corporation. What should he do?

Options

  • AIgnore it.
  • BTry to sell the information to a well-paying party on the dark web.
  • CNotify the web site owner so that corrective action be taken as soon as possible to patch the
  • DExploit the vulnerability without harming the web site owner so that attention be drawn to the

How the community answered

(24 responses)
  • B
    8% (2)
  • C
    88% (21)
  • D
    4% (1)

Why each option

When a researcher discovers a vulnerability, responsible disclosure requires notifying the affected organization directly so they can remediate it before malicious exploitation occurs.

AIgnore it.

Ignoring the vulnerability leaves it unpatched and exposes the organization's users to ongoing risk, which is an ethically negligent course of action.

BTry to sell the information to a well-paying party on the dark web.

Selling vulnerability information on the dark web is illegal under cybercrime statutes, constitutes trafficking in sensitive exploit data, and directly harms the affected organization and its users.

CNotify the web site owner so that corrective action be taken as soon as possible to patch theCorrect

Responsible disclosure (also called coordinated disclosure) is the ethical and legally sound practice of privately reporting a discovered vulnerability to the affected organization. This allows the owner to develop and deploy a patch before malicious actors can exploit it. It is the universally accepted standard in the security research community and protects both the researcher and the public.

DExploit the vulnerability without harming the web site owner so that attention be drawn to the

Exploiting a vulnerability without permission constitutes unauthorized access, which is illegal under laws such as the Computer Fraud and Abuse Act (CFAA) regardless of the researcher's stated intent or claimed lack of harm.

Concept tested: Responsible vulnerability disclosure ethics

Source: https://www.cisa.gov/coordinated-vulnerability-disclosure-process

Topics

#responsible disclosure#vulnerability reporting#ethical hacking#security ethics

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice