312-50 Question 18
Single answer▪ Information Security Laws and StandardsA consulting firm is hired to perform an external penetration test against a healthcare provider's public-facing systems. During kickoff, the client asks the lead ethical hacker to include a social engineering campaign against hospital staff and to test a cloud-hosted patient portal that is operated by a third-party vendor. The signed document currently authorizes scanning of the provider's IP ranges only and does not mention employee targeting, third-party assets, or handling of patient data. To remain compliant with information security laws and standards while reducing legal risk, what should the lead ethical hacker do FIRST before expanding the engagement?
- A
Proceed with the social engineering test because the client verbally approved it during the kickoff meeting, and begin testing the third-party portal if it resolves to the client's brand
- B
Update the rules of engagement and obtain explicit written authorization that defines scope, permitted techniques, affected third parties, and data-handling requirements before conducting those tests
- C
Start with limited phishing and credential harvesting against a small employee group to validate risk, then request formal approval if the results are significant
- D
Rely on the existing signed scope because cloud-hosted applications used by the client are implicitly included in any authorized penetration test
Show answer and explanation
Correct answer: B
Explanation
The best answer is to obtain explicit written authorization and update the rules of engagement before performing any out-of-scope activity. In ethical hacking, authorization must be specific, documented, and attributable to the party with authority over the target systems and personnel. This is especially important when the engagement expands from technical testing to social engineering, or from customer-owned assets to third-party hosted services. From a legal perspective, written authorization helps demonstrate that the activity is permitted and reduces the risk of violating computer misuse or unauthorized access laws. In a healthcare context, the engagement may also intersect with regulated data protections, so data handling, evidence collection, and incident escalation procedures should be defined in advance. This approach is consistent with common penetration testing best practices and standards guidance, including clear scope definition and rules of engagement as emphasized in frameworks such as NIST SP 800-115 and PTES, as well as contractual controls expected in regulated environments.
- A. Incorrect.
Incorrect. Verbal approval is not sufficient for expanding a penetration test into areas with separate legal and compliance implications. Social engineering introduces potential privacy, employment, and consent issues, and testing a third-party hosted portal without explicit authorization can expose the tester and client to unauthorized access claims. Brand association does not establish ownership or testing rights.
- B. Correct.
Correct. The tester should first ensure the engagement is formally updated in writing through a revised statement of work, rules of engagement, or authorization letter. This should clearly define the expanded scope, approved techniques such as phishing or pretexting, third-party authorization, points of contact, and requirements for handling regulated data such as protected health information. This aligns with standard penetration testing practice and helps address legal concerns under laws governing unauthorized access and sector-specific privacy obligations.
- C. Incorrect.
Incorrect. Even a limited phishing campaign or credential collection is an active test outside the original scope. Conducting it before written authorization creates legal and ethical exposure. The misconception is that small-scale testing is acceptable as a pilot, but scope and authorization requirements apply regardless of sample size.
- D. Incorrect.
Incorrect. Existing authorization for the provider's IP ranges does not automatically extend to third-party infrastructure or additional attack methods. Many cloud environments are owned or operated by vendors under separate contracts, and testing them may require the vendor's approval. Assuming implicit inclusion is a common but serious mistake in legally sensitive engagements.