nerdexam
EC-Council

312-50V9 · Question #348

A big company, who wanted to test their security infrastructure, wants to hire elite pen testers like you. During the interview, they asked you to show sample reports from previous penetration…

The correct answer is C. Decline but, provide references. A penetration tester should never share previous client reports, even under NDA, because those reports contain confidential client data that does not belong to the tester.

Introduction to Ethical Hacking

Question

A big company, who wanted to test their security infrastructure, wants to hire elite pen testers like you. During the interview, they asked you to show sample reports from previous penetration tests. What should you do?

Options

  • AShare reports, after NDA is signed
  • BShare full reports, not redacted
  • CDecline but, provide references
  • DShare full reports with redactions

How the community answered

(53 responses)
  • A
    6% (3)
  • B
    4% (2)
  • C
    77% (41)
  • D
    13% (7)

Why each option

A penetration tester should never share previous client reports, even under NDA, because those reports contain confidential client data that does not belong to the tester.

AShare reports, after NDA is signed

Signing a new NDA with the interviewer does not nullify or supersede the confidentiality obligations owed to the original client whose report is being shared.

BShare full reports, not redacted

Sharing full, unredacted reports directly exposes sensitive client infrastructure details, vulnerabilities, and data, constituting a clear breach of confidentiality and professional ethics.

CDecline but, provide referencesCorrect

Declining to share prior reports while offering professional references is the only ethically sound option, because penetration test reports are the property of the client who commissioned them and are covered under the NDA signed with that client. Sharing them - even with redactions - violates the confidentiality obligations already owed to previous clients. Providing references allows the prospective employer to verify competence without breaching existing agreements.

DShare full reports with redactions

Even redacted reports may reveal client identity, network topology, or methodology details that remain confidential, and sharing them still violates the original client NDA.

Concept tested: Penetration tester ethics and client confidentiality obligations

Source: http://www.pentest-standard.org/index.php/Pre-engagement

Topics

#penetration testing ethics#client confidentiality#professional conduct#report handling

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice