PT0-002 · Question #243
A tester who is performing a penetration test discovers an older firewall that is known to have serious vulnerabilities to remote attacks but is not part of the original list of IP addresses for the…
The correct answer is C. Notify the client about the firewall. The best option for the tester to take is to notify the client about the firewall. The firewall is not part of the original list of IP addresses for the engagement, which means it is out of scope and should not be tested without permission. The tester should inform the client…
Question
A tester who is performing a penetration test discovers an older firewall that is known to have serious vulnerabilities to remote attacks but is not part of the original list of IP addresses for the engagement. Which of the following is the BEST option for the tester to take?
Options
- ASegment the firewall from the cloud.
- BScan the firewall for vulnerabilities.
- CNotify the client about the firewall.
- DApply patches to the firewall.
How the community answered
(36 responses)- A6% (2)
- B14% (5)
- C72% (26)
- D8% (3)
Explanation
The best option for the tester to take is to notify the client about the firewall. The firewall is not part of the original list of IP addresses for the engagement, which means it is out of scope and should not be tested without permission. The tester should inform the client about the existence and potential risks of the firewall, and ask if they want to include it in the scope or not.
Topics
Community Discussion
No community discussion yet for this question.