nerdexam
CompTIA

PT0-002 · Question #396

An external consulting firm is hired to perform a penetration test and must keep the confidentiality of the security vulnerabilities and the private data found in a customer's systems. Which of the…

The correct answer is B. NDA. To ensure the confidentiality of security vulnerabilities and private data discovered during a penetration test, a Non-Disclosure Agreement (NDA) is the appropriate legal document. This agreement contractually obligates the consulting firm to protect sensitive information.

Planning and Scoping

Question

An external consulting firm is hired to perform a penetration test and must keep the confidentiality of the security vulnerabilities and the private data found in a customer's systems. Which of the following documents addresses this requirement?

Options

  • AROE
  • BNDA
  • CMOU
  • DSLA

How the community answered

(63 responses)
  • A
    2% (1)
  • B
    95% (60)
  • C
    3% (2)

Why each option

To ensure the confidentiality of security vulnerabilities and private data discovered during a penetration test, a Non-Disclosure Agreement (NDA) is the appropriate legal document. This agreement contractually obligates the consulting firm to protect sensitive information.

AROE

A Rules of Engagement (ROE) document outlines the scope, limitations, and authorized activities of a penetration test, but its primary focus is not on confidentiality of discovered data.

BNDACorrect

A Non-Disclosure Agreement (NDA) is a legally binding contract that establishes a confidential relationship between parties, obligating the recipient of sensitive information, such as security vulnerabilities or private data, to keep it secret and restrict its use. This directly addresses the requirement for the external consulting firm to maintain confidentiality during a penetration test.

CMOU

A Memorandum of Understanding (MOU) is a formal agreement between two or more parties outlining their intentions and understanding, often preceding a more formal contract, but it does not specifically focus on confidentiality of sensitive data like an NDA.

DSLA

A Service Level Agreement (SLA) defines the level of service expected from a vendor, specifying metrics and remedies, and does not primarily focus on the confidentiality of discovered information during a security assessment.

Concept tested: Penetration testing legal agreements - NDA

Source: https://www.irs.gov/pub/irs-utl/non-disclosure-agreement-nda.pdf

Topics

#Confidentiality#Legal Agreements#NDA#Penetration Testing Planning

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice