312-50 exam dumps

312-50 practice question 10 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 10

Single answer▪ Ethical Hacking Concepts

A healthcare organization hires an external security consultant to assess the security of a new patient portal before it goes live. The statement of work authorizes testing only against the portal's public web application and its supporting APIs during a two-week window, and it explicitly prohibits phishing, denial-of-service testing, and access to production patient records. During reconnaissance, the consultant discovers that the portal is hosted in a cloud environment shared with other business applications owned by the same company. Which action is the MOST appropriate for the consultant to take next to remain within ethical hacking principles and the agreed rules of engagement?

  1. A

    Expand testing to the other company-owned cloud applications because they are in the same hosting environment and may affect the portal's security posture

  2. B

    Attempt a controlled denial-of-service test against the portal during off-hours because availability is a key security concern for healthcare systems

  3. C

    Limit testing to the in-scope portal and APIs, document the shared-environment observation as a potential concern, and seek written authorization before testing any additional assets

  4. D

    Use harvested session tokens to access a small sample of real patient records because verifying data exposure is necessary to prove impact

Show answer and explanation

Correct answer: C

Explanation

The best answer is to stay strictly within the authorized scope and seek written approval before expanding testing. In CEH practice, ethical hacking differs from malicious activity because it is conducted with prior authorization, clearly defined scope, and documented rules of engagement. A shared cloud environment can introduce risk, but it does not automatically authorize testing of neighboring applications or infrastructure. Similarly, prohibited test types such as denial-of-service must not be performed, and restricted data such as production patient records must not be accessed unless explicitly approved. This aligns with standard penetration testing best practices: define scope, obtain written authorization, follow the rules of engagement, minimize business impact, and document observations that require client decision or scope expansion. These principles are consistent with industry guidance such as NIST SP 800-115 on technical security testing and common rules-of-engagement practices used in penetration testing engagements.

  • A. Incorrect.

    This is incorrect because ownership alone does not make adjacent systems in scope. Ethical hacking requires strict adherence to the defined scope and rules of engagement. Testing other applications without explicit authorization could expose the consultant and client to legal, operational, and compliance risk, especially in a shared cloud environment.

  • B. Incorrect.

    This is incorrect because the scenario explicitly prohibits denial-of-service testing. Even if availability is important, an ethical hacker must follow the signed authorization and testing constraints. Conducting DoS testing outside the agreed terms would violate professional and contractual boundaries.

  • C. Correct.

    This is correct because ethical hacking is defined by authorization, scope control, and compliance with the rules of engagement. The consultant should test only the public web application and supporting APIs that are explicitly in scope, avoid touching other cloud-hosted assets, and formally request written approval if expanded testing is needed. Documenting the shared-environment concern is appropriate because it preserves the finding without exceeding authorization.

  • D. Incorrect.

    This is incorrect because the statement of work explicitly prohibits access to production patient records. Ethical hackers should use nonproduction data or approved test accounts whenever possible. Accessing real patient records, even in a limited way, could violate privacy requirements and exceed the authorized objective.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam