312-50 exam dumps

312-50 practice question 11 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 11

Single answer▪ Ethical Hacking Concepts

A company hires a security consultant to evaluate the resilience of its newly deployed external web application. During the kickoff meeting, the consultant is told to "test anything you can reach from the internet" because the leadership wants a realistic assessment. No written authorization, scope boundaries, or rules of engagement have been finalized yet. The consultant discovers that the application is hosted in a cloud environment shared with other business units and integrated with a third-party payment gateway. What should the consultant do FIRST to remain aligned with ethical hacking principles and professional practice?

  1. A

    Begin passive reconnaissance immediately because it does not directly interact with the target and therefore does not require formal approval

  2. B

    Start vulnerability scanning only against the web application URL, since limiting activity to one hostname keeps the test ethical

  3. C

    Obtain a signed authorization with a clearly defined scope, rules of engagement, and third-party permissions before performing any testing

  4. D

    Test the payment gateway integration first, because third-party services are often the weakest link and provide the most realistic results

Show answer and explanation

Correct answer: C

Explanation

The key ethical hacking concept being tested is that authorization and scope come before technical activity. In professional penetration testing and CEH-aligned practice, a tester must have documented permission and a clear rules-of-engagement document before beginning reconnaissance, scanning, exploitation, or testing of integrated services. This is particularly important in shared cloud environments and when third-party providers are involved, because unauthorized testing may affect assets owned by others. Best practice is to define in writing the targets, exclusions, testing windows, communication paths, data handling requirements, and whether third-party services are in scope. This aligns with standard penetration testing methodology and common industry guidance such as Rules of Engagement in penetration testing frameworks and provider policies for authorized security testing.

  • A. Incorrect.

    This is incorrect. Even passive reconnaissance can create legal and contractual issues if performed without formal authorization in a professional engagement. Ethical hacking is defined not just by technical methods, but by permission, scope, and documented approval. Assuming passive activities are exempt is a common misconception.

  • B. Incorrect.

    This is incorrect. Restricting testing to a single hostname does not solve the core problem: the consultant still lacks written authorization and formal scope. In addition, a hostname may resolve to infrastructure shared with other systems, and scanning without approved rules of engagement could affect production services or third-party assets.

  • C. Correct.

    This is correct. The first step in an ethical hacking engagement is to ensure explicit written authorization, a well-defined scope, rules of engagement, timing, constraints, and approval for any third-party or shared-cloud components. This protects the client, the consultant, and unrelated parties, and it establishes what is permitted before reconnaissance, scanning, or exploitation begins.

  • D. Incorrect.

    This is incorrect. Testing third-party payment infrastructure without explicit permission is especially risky and likely outside the consultant's authority. Third-party systems require specific authorization, and many cloud and payment providers prohibit unauthorized testing. Choosing a likely weak point does not override legal and ethical requirements.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam