nerdexam
EC-Council

312-50V9 · Question #338

One of the Forbes 500 companies has been subjected to a large scale attack. You are one of the shortlisted pen testers that they may hire. During the interview with the CIO, he emphasized that he…

The correct answer is C. Explain to the CIO that you cannot eliminate all risk, but you will be able to reduce risk to. A core principle of risk management is that risk can never be fully eliminated, only reduced to an acceptable residual level, and a penetration tester must correct this misunderstanding before engagement begins.

Introduction to Ethical Hacking

Question

One of the Forbes 500 companies has been subjected to a large scale attack. You are one of the shortlisted pen testers that they may hire. During the interview with the CIO, he emphasized that he wants to totally eliminate all risks. What is one of the first things you should do when hired?

Options

  • AInterview all employees in the company to rule out possible insider threats.
  • BEstablish attribution to suspected attackers.
  • CExplain to the CIO that you cannot eliminate all risk, but you will be able to reduce risk to
  • DStart the Wireshark application to start sniffing network traffic.

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    4% (2)
  • C
    82% (42)
  • D
    10% (5)

Why each option

A core principle of risk management is that risk can never be fully eliminated, only reduced to an acceptable residual level, and a penetration tester must correct this misunderstanding before engagement begins.

AInterview all employees in the company to rule out possible insider threats.

Interviewing employees for insider threat assessment is a valid security activity, but it is premature to begin any technical work before correcting the CIO's fundamentally flawed assumption that all risk can be eliminated.

BEstablish attribution to suspected attackers.

Attacker attribution is relevant to incident response and legal proceedings, but it does not address the critical misunderstanding the CIO holds about total risk elimination, which must be resolved first to frame the entire engagement correctly.

CExplain to the CIO that you cannot eliminate all risk, but you will be able to reduce risk toCorrect

Total risk elimination is impossible in any real-world environment - organizations can only identify, mitigate, transfer, or accept risks to reduce them to a tolerable residual level. A penetration tester must establish this accurate expectation with the CIO at the outset to ensure the engagement scope, success criteria, and deliverables are grounded in achievable outcomes rather than an unattainable goal.

DStart the Wireshark application to start sniffing network traffic.

Immediately launching Wireshark to capture network traffic is unauthorized without a defined scope and rules of engagement, and it bypasses the essential first step of aligning expectations with the CIO about what risk reduction can realistically achieve.

Concept tested: Risk management principles and stakeholder expectation setting

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#risk management#penetration testing#ethics#risk reduction

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice