312-50 Question 16
Single answer▪ Information Security Laws and StandardsA U.S.-based security consulting firm is hired to perform an external penetration test against a retail company that stores payment card data and also processes personal data of EU customers. During scoping, the client asks the tester to capture sample database records containing full card numbers and customer contact details so the firm can include them in the final report as proof of impact. The engagement is scheduled for next week, but the signed rules of engagement do not mention handling live cardholder data or personally identifiable information (PII). What is the MOST appropriate action for the ethical hacker before proceeding?
- A
Proceed with the test and collect a limited number of real records because documenting actual exposed data is necessary to demonstrate business impact
- B
Refuse to test the target entirely because systems involving payment cards or EU personal data cannot be legally tested by third parties
- C
Pause and update the scope, rules of engagement, and data-handling requirements to explicitly authorize how cardholder data and PII will be accessed, minimized, protected, stored, and reported before any collection occurs
- D
Continue testing, but replace any real data with fabricated examples in the report without informing the client, since this avoids compliance issues
Show answer and explanation
Correct answer: C
Explanation
The best answer is to pause and formally address the legal and compliance implications before collecting live sensitive data. In real engagements, an ethical hacker must operate under explicit written authorization and a well-defined rules of engagement document. When testing environments involving cardholder data, PCI DSS is directly relevant because it requires protection of account data and strong controls around access, storage, transmission, and retention. If personal data of EU residents is involved, GDPR principles such as data minimization, purpose limitation, and security of processing should be considered. A tester should only collect the minimum evidence necessary, and any collection, storage, transfer, and reporting of sensitive data should be documented and approved in advance. This aligns with common penetration testing best practices, including clear scoping, legal authorization, evidence handling procedures, and secure reporting. In CEH-style scenarios, the safest and most professional response is not to over-collect data for convenience, but to ensure the engagement is governed by appropriate legal and operational controls before proceeding.
- A. Incorrect.
This is incorrect because collecting real cardholder data and PII without explicit authorization and handling procedures creates legal, contractual, and compliance risk. PCI DSS requires strict protection of account data, and privacy laws such as the GDPR require data minimization and appropriate safeguards when personal data is processed. In a penetration test, proof of impact does not automatically justify unrestricted collection of sensitive data.
- B. Incorrect.
This is incorrect because third-party testing is not prohibited simply because payment card data or EU personal data is involved. In fact, organizations commonly use authorized assessors and penetration testers. The key issue is obtaining clear authorization, defining scope, and establishing compliant handling procedures. The misconception here is confusing regulated data with a ban on testing, rather than recognizing the need for stricter controls.
- C. Correct.
This is correct because the tester should ensure the engagement documentation explicitly covers authorization, scope, and lawful handling of sensitive data before accessing or collecting it. For payment card environments, PCI DSS requires protection of stored account data and careful control of access. For EU personal data, GDPR principles such as data minimization, purpose limitation, and integrity/confidentiality apply. Updating the rules of engagement and data-handling plan helps ensure the test remains authorized, defensible, and compliant while still allowing evidence collection if approved.
- D. Incorrect.
This is incorrect because silently altering reporting evidence is unethical and unprofessional. If the client requested proof using real data, the tester must not unilaterally substitute fabricated examples without discussion. The proper course is to agree in advance on what evidence can be collected and how it will be sanitized or redacted. This option reflects a common mistake of trying to solve a compliance problem through undocumented deception instead of governance and consent.