312-50V9 · Question #348
A big company, who wanted to test their security infrastructure, wants to hire elite pen testers like you. During the interview, they asked you to show sample reports from previous penetration…
The correct answer is C. Decline but, provide references. A penetration tester should never share previous client reports, even under NDA, because those reports contain confidential client data that does not belong to the tester.
Question
A big company, who wanted to test their security infrastructure, wants to hire elite pen testers like you. During the interview, they asked you to show sample reports from previous penetration tests. What should you do?
Options
- AShare reports, after NDA is signed
- BShare full reports, not redacted
- CDecline but, provide references
- DShare full reports with redactions
How the community answered
(53 responses)- A6% (3)
- B4% (2)
- C77% (41)
- D13% (7)
Why each option
A penetration tester should never share previous client reports, even under NDA, because those reports contain confidential client data that does not belong to the tester.
Signing a new NDA with the interviewer does not nullify or supersede the confidentiality obligations owed to the original client whose report is being shared.
Sharing full, unredacted reports directly exposes sensitive client infrastructure details, vulnerabilities, and data, constituting a clear breach of confidentiality and professional ethics.
Declining to share prior reports while offering professional references is the only ethically sound option, because penetration test reports are the property of the client who commissioned them and are covered under the NDA signed with that client. Sharing them - even with redactions - violates the confidentiality obligations already owed to previous clients. Providing references allows the prospective employer to verify competence without breaching existing agreements.
Even redacted reports may reveal client identity, network topology, or methodology details that remain confidential, and sharing them still violates the original client NDA.
Concept tested: Penetration tester ethics and client confidentiality obligations
Source: http://www.pentest-standard.org/index.php/Pre-engagement
Topics
Community Discussion
No community discussion yet for this question.