nerdexam
CompTIA

PT0-002 · Question #591

While scanning a network during a contracted assessment, a penetration tester realizes that patch management is outdated with a known critical vulnerability present on organizational systems. Which…

The correct answer is A. Contact the client immediately. Upon discovering a critical, unpatched vulnerability during a contracted penetration test, the penetration tester's immediate priority is to inform the client. This action aligns with ethical hacking principles and the scope of a penetration test.

Engagement management

Question

While scanning a network during a contracted assessment, a penetration tester realizes that patch management is outdated with a known critical vulnerability present on organizational systems. Which of the following actions should the penetration tester take next?

Options

  • AContact the client immediately.
  • BDeploy the patch.
  • CStop the engagement.
  • DDiscuss with the systems administrator.

How the community answered

(33 responses)
  • A
    79% (26)
  • B
    3% (1)
  • C
    6% (2)
  • D
    12% (4)

Why each option

Upon discovering a critical, unpatched vulnerability during a contracted penetration test, the penetration tester's immediate priority is to inform the client. This action aligns with ethical hacking principles and the scope of a penetration test.

AContact the client immediately.Correct

Ethical penetration testing mandates immediate notification to the client regarding critical vulnerabilities that pose a significant and imminent risk to their systems. This ensures the client can take swift action to mitigate the risk and aligns with the agreed-upon scope of work, which typically includes reporting such findings.

BDeploy the patch.

Deploying a patch is outside the scope of a penetration tester's role, which is to identify and report vulnerabilities, not to remediate them directly.

CStop the engagement.

Stopping the engagement without client notification would leave the critical vulnerability unaddressed and fail to fulfill the purpose of the contracted assessment.

DDiscuss with the systems administrator.

Discussing with only the systems administrator might not be the appropriate chain of command for critical findings, as the client's management or designated point of contact needs to be informed for broader organizational action.

Concept tested: Ethical hacking conduct, critical vulnerability reporting

Topics

#Penetration testing ethics#Client notification#Critical vulnerability handling#Professional conduct

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice