nerdexam
CompTIA

PT0-002 · Question #363

During an engagement with a financial institution, a penetration tester found hard-coded credentials in a publicly accessible code repository. Those credentials allowed the penetration tester to…

The correct answer is D. Report the findings to the customer's technical contact immediately. When a penetration tester discovers a critical vulnerability, such as hard-coded credentials leading to PII exposure, they must immediately report it to the customer's technical contact. This urgent notification is crucial to prevent further data compromise and allow the…

Reporting and Communication

Question

During an engagement with a financial institution, a penetration tester found hard-coded credentials in a publicly accessible code repository. Those credentials allowed the penetration tester to access PII from many of the institution's customers and services that are hosted by a cloud provider. Which of the following actions should the penetration tester do next?

Options

  • AProceed with the engagement and add the evidence in the final report
  • BKeep the found credentials and use them during the engagement
  • CDisclose the findings through a bug bounty platform
  • DReport the findings to the customer's technical contact immediately

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    13% (6)
  • D
    80% (37)

Why each option

When a penetration tester discovers a critical vulnerability, such as hard-coded credentials leading to PII exposure, they must immediately report it to the customer's technical contact. This urgent notification is crucial to prevent further data compromise and allow the organization to mitigate the risk promptly.

AProceed with the engagement and add the evidence in the final report

Proceeding with the engagement without immediate notification of a critical finding like PII exposure is irresponsible and unethical, as it delays mitigation of an active threat.

BKeep the found credentials and use them during the engagement

Keeping and using credentials that expose PII without immediate disclosure is unethical and could lead to further compromise or liability for the tester.

CDisclose the findings through a bug bounty platform

Disclosing findings through a public bug bounty platform before reporting to the customer is inappropriate and could expose sensitive information to a wider audience, violating client trust and data privacy.

DReport the findings to the customer's technical contact immediatelyCorrect

Best practice and ethical guidelines for penetration testing require immediate reporting of critical findings, especially those involving PII exposure, to the designated customer contact. This allows the client to take rapid action to mitigate the severe risk and prevent further compromise.

Concept tested: Penetration testing ethics and critical vulnerability reporting

Topics

#Incident Handling#Ethical Hacking#Vulnerability Disclosure#Customer Communication

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice