provocativo
_
Blog
Incidents
Glossary
Labs
Quizzes
Tools
Arsenal
Certifications
Login
Live threats
Open feed
·
T
all quizzes
Hacker Ethics 101
beginner
Q1
/10
45s
A pentester discovers a vulnerability in a client's web app. The Rules of Engagement clearly limit testing to the staging environment. The vuln also exists in production. The pentester exploits production to 'prove impact'. Is this legal/ethical?
1
Both legal and ethical — proof of impact justifies it
2
Legal because the client owns the system; unethical because it lies outside scope
3
Neither — it exceeds authorized scope, so it is unauthorized access under most computer-misuse laws
4
Ethical but not legal — the client cannot waive criminal law