provocativo_
all quizzes
beginnerQ1/1045s

A pentester discovers a vulnerability in a client's web app. The Rules of Engagement clearly limit testing to the staging environment. The vuln also exists in production. The pentester exploits production to 'prove impact'. Is this legal/ethical?