nerdexam
(ISC)2

SSCP · Question #376

Which of the following statements pertaining to ethical hacking is incorrect?

The correct answer is D. Ethical hackers never use tools that have the potential of affecting servers or services. This statement is false and therefore the correct answer. Ethical hackers routinely use tools - port scanners (nmap), vulnerability scanners (Nessus), exploitation frameworks (Metasploit), password crackers - that absolutely have the potential to impact servers or services. The…

Submitted by tyler.j· Apr 18, 2026Security Concepts and Practices

Question

Which of the following statements pertaining to ethical hacking is incorrect?

Options

  • AAn organization should use ethical hackers who do not sell auditing, hardware, software,
  • BTesting should be done remotely to simulate external threats.
  • CEthical hacking should not involve writing to or modifying the target systems negatively.
  • DEthical hackers never use tools that have the potential of affecting servers or services.

How the community answered

(34 responses)
  • B
    3% (1)
  • C
    3% (1)
  • D
    94% (32)

Explanation

This statement is false and therefore the correct answer. Ethical hackers routinely use tools - port scanners (nmap), vulnerability scanners (Nessus), exploitation frameworks (Metasploit), password crackers - that absolutely have the potential to impact servers or services. The key distinction is that they use such tools with explicit written authorization and with appropriate care to minimize disruption. Statements A (not selling auditing products to avoid conflicts of interest), B (testing remotely to simulate external threats), and C (not causing lasting negative modifications to target systems) are all accurate and accepted ethical hacking principles.

Topics

#Ethical Hacking Principles#Penetration Testing Ethics#Professional Ethics#Security Auditing

Community Discussion

No community discussion yet for this question.

Full SSCP Practice