PT0-002 · Question #361
A penetration tester discovers passwords in a publicly available data breach during the reconnaissance phase of the penetration test. Which of the following is the best action for the tester to take?
The correct answer is C. Contact the client and inform them of the breach. The best action for a penetration tester discovering client passwords in a public data breach is to immediately contact the client and inform them of the compromised credentials.
Question
A penetration tester discovers passwords in a publicly available data breach during the reconnaissance phase of the penetration test. Which of the following is the best action for the tester to take?
Options
- AAdd the passwords to an appendix in the penetration test report.
- BDo nothing. Using passwords from breached data is unethical.
- CContact the client and inform them of the breach.
- DUse the passwords in a credential stuffing attack when the external penetration test begins.
How the community answered
(58 responses)- A3% (2)
- B5% (3)
- C79% (46)
- D12% (7)
Why each option
The best action for a penetration tester discovering client passwords in a public data breach is to immediately contact the client and inform them of the compromised credentials.
Adding the passwords to a report appendix is insufficient; immediate action is required due to the high risk of publicly available compromised credentials.
Doing nothing would be a dereliction of professional duty, as the information represents an active and critical risk to the client.
Discovering publicly leaked passwords of the client's employees or systems constitutes a significant and immediate security risk. The ethical and professional responsibility of a penetration tester is to promptly notify the client so they can take immediate action, such as enforcing password resets, to mitigate the risk before these credentials can be exploited. This prioritization ensures client security above the assessment's technical goals.
While using these passwords for credential stuffing might be a valid next step if approved and in scope, the best first action is to inform the client of the compromise itself, allowing them to remediate proactively.
Concept tested: Ethical conduct in penetration testing
Topics
Community Discussion
No community discussion yet for this question.