PT0-002 · Question #591
While scanning a network during a contracted assessment, a penetration tester realizes that patch management is outdated with a known critical vulnerability present on organizational systems. Which…
The correct answer is A. Contact the client immediately. Upon discovering a critical, unpatched vulnerability during a contracted penetration test, the penetration tester's immediate priority is to inform the client. This action aligns with ethical hacking principles and the scope of a penetration test.
Question
While scanning a network during a contracted assessment, a penetration tester realizes that patch management is outdated with a known critical vulnerability present on organizational systems. Which of the following actions should the penetration tester take next?
Options
- AContact the client immediately.
- BDeploy the patch.
- CStop the engagement.
- DDiscuss with the systems administrator.
How the community answered
(33 responses)- A79% (26)
- B3% (1)
- C6% (2)
- D12% (4)
Why each option
Upon discovering a critical, unpatched vulnerability during a contracted penetration test, the penetration tester's immediate priority is to inform the client. This action aligns with ethical hacking principles and the scope of a penetration test.
Ethical penetration testing mandates immediate notification to the client regarding critical vulnerabilities that pose a significant and imminent risk to their systems. This ensures the client can take swift action to mitigate the risk and aligns with the agreed-upon scope of work, which typically includes reporting such findings.
Deploying a patch is outside the scope of a penetration tester's role, which is to identify and report vulnerabilities, not to remediate them directly.
Stopping the engagement without client notification would leave the critical vulnerability unaddressed and fail to fulfill the purpose of the contracted assessment.
Discussing with only the systems administrator might not be the appropriate chain of command for critical findings, as the client's management or designated point of contact needs to be informed for broader organizational action.
Concept tested: Ethical hacking conduct, critical vulnerability reporting
Topics
Community Discussion
No community discussion yet for this question.