nerdexam
(ISC)2(ISC)2

CISSP · Question #69

CISSP Question #69: Real Exam Question with Answer & Explanation

The correct answer is D: The behavior is not ethical because such a tool could be leaked on the Internet.. Creating a virus creation tool that can generate thousands of polymorphic viruses is not ethical, even if the intention is to use it in a controlled environment to test the company's next generation virus scanning software. Such a tool could be leaked on the Internet, either inte

Submitted by takeshi77· Mar 5, 2026Security and Risk Management

Question

An engineer in a software company has created a virus creation tool. The tool can generate thousands of polymorphic viruses. The engineer is planning to use the tool in a controlled environment to test the company's next generation virus scanning software. Which would BEST describe the behavior of the engineer and why?

Options

  • AThe behavior is ethical because the tool will be used to create a better virus scanner.
  • BThe behavior is ethical because any experienced programmer could create such a tool.
  • CThe behavior is not ethical because creating any kind of virus is bad.
  • DThe behavior is not ethical because such a tool could be leaked on the Internet.

Explanation

Creating a virus creation tool that can generate thousands of polymorphic viruses is not ethical, even if the intention is to use it in a controlled environment to test the company's next generation virus scanning software. Such a tool could be leaked on the Internet, either intentionally or accidentally, and fall into the hands of malicious actors who could use it to create and spread harmful viruses that could compromise the security and privacy of millions of users and systems. The engineer should follow the code of ethics and professional conduct of the ISC2, which states that members and certificate holders shall protect society, the common good, necessary public trust and confidence, and the infrastructure.

Topics

#ethics in security#software development security#risk assessment#responsible disclosure

Community Discussion

No community discussion yet for this question.

Full CISSP PracticeBrowse All CISSP Questions