PT0-002 · Question #18
A company becomes concerned when the security alarms are triggered during a penetration test. Which of the following should the company do NEXT?
The correct answer is C. Deconflict with the penetration tester. Deconfliction is the process of contacting the penetration testing team to verify whether a detected alert was generated by their authorized activities or by a real, unrelated threat actor. This is a critical step because both scenarios are possible simultaneously. Halting the…
Question
A company becomes concerned when the security alarms are triggered during a penetration test. Which of the following should the company do NEXT?
Options
- AHalt the penetration test.
- BConduct an incident response.
- CDeconflict with the penetration tester.
- DAssume the alert is from the penetration test.
How the community answered
(30 responses)- A10% (3)
- B3% (1)
- C80% (24)
- D7% (2)
Explanation
Deconfliction is the process of contacting the penetration testing team to verify whether a detected alert was generated by their authorized activities or by a real, unrelated threat actor. This is a critical step because both scenarios are possible simultaneously. Halting the test (A) is premature without first checking. Launching a full incident response (B) wastes resources if the alert is simply from the tester. Assuming the alert is from the test (D) is dangerous-it could allow a real attacker to go undetected. The get-out-of-jail card / Rules of Engagement documentation and the deconfliction contact process are established precisely for this situation.
Topics
Community Discussion
No community discussion yet for this question.