312-50V9 · Question #338
One of the Forbes 500 companies has been subjected to a large scale attack. You are one of the shortlisted pen testers that they may hire. During the interview with the CIO, he emphasized that he…
The correct answer is C. Explain to the CIO that you cannot eliminate all risk, but you will be able to reduce risk to. A core principle of risk management is that risk can never be fully eliminated, only reduced to an acceptable residual level, and a penetration tester must correct this misunderstanding before engagement begins.
Question
One of the Forbes 500 companies has been subjected to a large scale attack. You are one of the shortlisted pen testers that they may hire. During the interview with the CIO, he emphasized that he wants to totally eliminate all risks. What is one of the first things you should do when hired?
Options
- AInterview all employees in the company to rule out possible insider threats.
- BEstablish attribution to suspected attackers.
- CExplain to the CIO that you cannot eliminate all risk, but you will be able to reduce risk to
- DStart the Wireshark application to start sniffing network traffic.
How the community answered
(51 responses)- A4% (2)
- B4% (2)
- C82% (42)
- D10% (5)
Why each option
A core principle of risk management is that risk can never be fully eliminated, only reduced to an acceptable residual level, and a penetration tester must correct this misunderstanding before engagement begins.
Interviewing employees for insider threat assessment is a valid security activity, but it is premature to begin any technical work before correcting the CIO's fundamentally flawed assumption that all risk can be eliminated.
Attacker attribution is relevant to incident response and legal proceedings, but it does not address the critical misunderstanding the CIO holds about total risk elimination, which must be resolved first to frame the entire engagement correctly.
Total risk elimination is impossible in any real-world environment - organizations can only identify, mitigate, transfer, or accept risks to reduce them to a tolerable residual level. A penetration tester must establish this accurate expectation with the CIO at the outset to ensure the engagement scope, success criteria, and deliverables are grounded in achievable outcomes rather than an unattainable goal.
Immediately launching Wireshark to capture network traffic is unauthorized without a defined scope and rules of engagement, and it bypasses the essential first step of aligning expectations with the CIO about what risk reduction can realistically achieve.
Concept tested: Risk management principles and stakeholder expectation setting
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.