nerdexam
CompTIA

PT0-002 · Question #367

A penetration tester requested, without express authorization, that a CVE number be assigned for a new vulnerability found on an internal client application. Which of the following did the…

The correct answer is A. ROE. ROE stands for Rules of Engagement, which are the guidelines and limitations that define the scope, objectives, and methods of a penetration testing engagement. ROE should be agreed upon by both the client and the tester before the testing begins, and they should include the…

Engagement management

Question

A penetration tester requested, without express authorization, that a CVE number be assigned for a new vulnerability found on an internal client application. Which of the following did the penetration tester most likely breach?

Options

  • AROE
  • BSLA
  • CNDA
  • DSOW

How the community answered

(64 responses)
  • A
    72% (46)
  • B
    16% (10)
  • C
    8% (5)
  • D
    5% (3)

Explanation

ROE stands for Rules of Engagement, which are the guidelines and limitations that define the scope, objectives, and methods of a penetration testing engagement. ROE should be agreed upon by both the client and the tester before the testing begins, and they should include the authorization to perform certain actions, such as requesting CVE numbers, disclosing vulnerabilities, or exploiting systems. By requesting a CVE number without express authorization, the penetration tester most likely breached the ROE and violated the client's trust and

Topics

#Rules of Engagement#Penetration testing ethics#Authorization#Vulnerability disclosure

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice