312-50 Question 318
Single answer▪ Attack Authorization SchemesA healthcare company hires an ethical hacker to perform a penetration test against its patient portal and internal network. During planning, the tester learns that the IT director verbally approved the test, but the legal department has not signed the rules of engagement, no written authorization identifies in-scope IP ranges, and no emergency contact or stop-testing procedure has been documented. The engagement is scheduled to begin in two hours. What should the ethical hacker do FIRST to remain compliant with proper attack authorization practices?
- A
Begin only passive reconnaissance because verbal approval is enough for non-intrusive testing
- B
Proceed with testing the public-facing portal but avoid the internal network until written approval is received
- C
Delay the engagement until a formal written authorization and rules of engagement are completed and approved
- D
Start exploitation against a limited set of targets and document any legal concerns in the final report
Show answer and explanation
Correct answer: C
Explanation
In CEH-aligned practice, attack authorization schemes are foundational to lawful and professional security testing. Before any reconnaissance, scanning, or exploitation begins, the tester should obtain written authorization from an authorized representative and ensure the rules of engagement are finalized. These documents should define scope, targets, time windows, constraints, points of contact, data handling, escalation paths, and conditions for halting the test. This approach aligns with widely accepted penetration testing best practices such as formal pre-engagement interactions described in standards and methodologies like PTES and NIST guidance on planning and rules of behavior. In regulated environments such as healthcare, the need for clear authorization is even more important because poorly defined testing can affect protected systems, availability, and compliance obligations.
- A. Incorrect.
Incorrect. Passive reconnaissance may appear low risk, but it is still part of an assessment and should be covered by explicit authorization. In attack authorization schemes, verbal approval alone is insufficient because it does not clearly define scope, timing, ownership, liability, or permitted techniques. A common misconception is that passive activities do not require authorization; however, proper engagement governance requires written approval before any testing begins.
- B. Incorrect.
Incorrect. Limiting testing to an internet-facing portal does not solve the core problem: there is still no formal written authorization, no approved scope, and no signed rules of engagement. Public exposure of a system does not imply consent to test it. Candidates may choose this option because it seems cautious, but it still exposes both the tester and client to legal and operational risk.
- C. Correct.
Correct. The ethical hacker should pause the engagement until formal written authorization is in place, including clearly defined scope, approved testing window, permitted and prohibited activities, emergency contacts, and stop-testing procedures. This is the safest and professionally correct first action under standard penetration testing best practices. Attack authorization exists to ensure explicit consent and reduce legal, compliance, and business risk before any security testing starts.
- D. Incorrect.
Incorrect. Beginning exploitation without finalized authorization is inappropriate, even if the tester plans to note concerns later. Documentation in the final report does not retroactively create consent or protect against unauthorized activity. This option reflects a dangerous misconception that post-engagement reporting can compensate for missing pre-engagement approval.