CompTIA
PT0-002 · Question #11
Which of the following should a penetration tester do NEXT after identifying that an application being tested has already been compromised with malware?
The correct answer is E. Stop the assessment and inform the emergency contact. Standard procedure when you establish an active/current security breach, is to stop the test an inform the Emergency Contact.
Engagement management
Question
Which of the following should a penetration tester do NEXT after identifying that an application being tested has already been compromised with malware?
Options
- AAnalyze the malware to see what it does.
- BCollect the proper evidence and then remove the malware.
- CDo a root-cause analysis to find out how the malware got in.
- DRemove the malware immediately.
- EStop the assessment and inform the emergency contact.
How the community answered
(44 responses)- A14% (6)
- B2% (1)
- C5% (2)
- D7% (3)
- E73% (32)
Explanation
Standard procedure when you establish an active/current security breach, is to stop the test an inform the Emergency Contact.
Topics
#Incident Response#Professional Conduct#Engagement Scope#Communication Protocols
Community Discussion
No community discussion yet for this question.