nerdexam
GIAC

GPEN · Question #469

You've been contracted by the owner of a secure facility to try and break into their office in the middle of the night. Your client requested photographs of any sensitive information found as proof of

The correct answer is B. Ethical Hacking. A contracted physical intrusion test with client authorization and evidence-gathering requirements is a classic example of ethical hacking, which encompasses authorized real-world attack simulations including physical security breaches.

Penetration Testing Foundations & Reconnaissance

Question

You've been contracted by the owner of a secure facility to try and break into their office in the middle of the night. Your client requested photographs of any sensitive information found as proof of your accomplishments. The job you've been hired to perform is an example of what practice?

Options

  • APenetration Testing
  • BEthical Hacking
  • CVulnerability Assessing
  • DSecurity Auditing

How the community answered

(57 responses)
  • A
    16% (9)
  • B
    75% (43)
  • C
    5% (3)
  • D
    4% (2)

Why each option

A contracted physical intrusion test with client authorization and evidence-gathering requirements is a classic example of ethical hacking, which encompasses authorized real-world attack simulations including physical security breaches.

APenetration Testing

Penetration testing typically refers to technical or network-focused authorized attack simulations and is narrower in scope than the broad physical intrusion engagement described in the scenario.

BEthical HackingCorrect

Ethical hacking is the authorized practice of simulating real-world attacks - including physical break-ins - against a target with the owner's explicit permission and defined scope, with the goal of identifying exploitable weaknesses. The client contract, authorization to enter the facility, and requirement to produce photographic evidence all define this engagement as ethical hacking rather than a criminal act.

CVulnerability Assessing

Vulnerability assessing involves identifying and cataloging weaknesses without actively exploiting or demonstrating them - physically breaking in and collecting evidence goes well beyond passive assessment.

DSecurity Auditing

Security auditing evaluates compliance, policies, and procedures against established standards and does not involve actively attempting to breach physical security controls.

Concept tested: Ethical hacking definition including physical security testing

Source: https://www.eccouncil.org/ethical-hacking/

Topics

#ethical hacking#physical penetration testing#engagement types#definitions

Community Discussion

No community discussion yet for this question.

Full GPEN Practice