A security company has been contracted to perform a scoped insider-threat assessment to try to gain access to the human resources server that houses PII and salary data. The penetration testers have been given an internal network starting position.
Which of the following actions, if performed, would be ethical within the scope of the assessment?
Correct Answer: A. Exploiting a configuration weakness in the SQL database
In a scoped insider-threat assessment, the goal is to simulate an internal attacker (e.g., a disgruntled employee or compromised insider) to test how easily they can access sensitive data, such as PII and salary records on the HR server.
Why the Other Options Are Incorrect:
Intercepting outbound TLS traffic
This involves man-in-the-middle (MITM) attacks and breaking encryption, which may lead to legal and ethical violations if not explicitly permitted.
MITM attacks on TLS traffic could violate privacy laws and breach unauthorized data.
Gaining access to hosts by injecting malware into the enterprise-wide update server
Deploying malware or modifying enterprise-wide updates can have severe operational consequences and could be considered malicious hacking rather than ethical penetration testing.
Injecting malware into enterprise-wide systems is unethical and dangerous.
Leveraging a vulnerability on the internal CA to issue fraudulent client certificates
An internal certificate authority (CA) is a highly sensitive infrastructure component used for authentication and encryption.
Creating fake client certificates is unethical and could lead to unintended consequences.
Establishing and maintaining persistence on the domain controller
The domain controller (DC) is the heart of an organization’s authentication and access control system.
Maintaining persistence on the domain controller is too invasive and likely out of scope.
No Payment Cards Needed
Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.
You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams