312-50 exam dumps

312-50 practice question 320 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 320

Single answer▪ Attack Authorization Schemes

A consulting firm has been hired to perform a penetration test against a retail company. During the kickoff meeting, the client asks the ethical hacker to test whether a recently acquired subsidiary can be used as a pivot point into the parent company's network. The subsidiary's systems are owned by a different legal entity, and its IT manager verbally agrees to the test. To ensure the engagement is properly authorized and legally defensible, what is the BEST action for the ethical hacker before attempting any testing against the subsidiary?

  1. A

    Proceed with testing because the parent company initiated the engagement and the subsidiary's IT manager provided verbal approval

  2. B

    Begin only passive reconnaissance against the subsidiary until written approval can be obtained later

  3. C

    Obtain explicit written authorization that identifies the subsidiary's assets in scope and is signed by an authorized representative of that legal entity

  4. D

    Rely on the master services agreement with the consulting firm, because it implicitly covers any organization affiliated with the client

Show answer and explanation

Correct answer: C

Explanation

In CEH and real-world engagements, attack authorization schemes are fundamentally about ensuring the tester has clear, documented permission from the proper asset owner before conducting any security testing. When multiple legal entities are involved, such as subsidiaries, affiliates, cloud providers, or partners, authorization must be validated for each environment in scope. The best practice is to use formal written authorization and rules of engagement that define scope, targets, timing, permitted techniques, limitations, and points of contact. This is consistent with standard penetration testing practices reflected in professional methodologies such as NIST SP 800-115 and PTES, both of which emphasize explicit authorization, scope definition, and legal clarity before testing begins. The key applied lesson is that ownership and legal authority matter more than convenience or informal approval.

  • A. Incorrect.

    This is incorrect because authorization for offensive security testing must come from an authorized party with legal authority over the assets being tested. A parent company initiating the engagement does not automatically grant permission to test a separately owned or separately incorporated subsidiary, and verbal approval from an IT manager may not be sufficient or legally binding. Attack authorization schemes require clear, documented consent tied to ownership and scope.

  • B. Incorrect.

    This is incorrect because even passive reconnaissance can constitute security testing activity if conducted against systems not yet explicitly authorized. A common misconception is that only active exploitation requires approval, but professional rules of engagement should define what is permitted before any testing begins. Waiting for written authorization after starting creates unnecessary legal and contractual risk.

  • C. Correct.

    This is correct because the safest and most defensible approach is to obtain written authorization, typically through a signed rules-of-engagement document, statement of work, or authorization-to-test letter, that specifically names the subsidiary's systems or ranges as in scope. The signature must come from someone with authority over that legal entity's assets. This aligns with standard penetration testing best practices requiring explicit scope, ownership validation, and documented consent before testing.

  • D. Incorrect.

    This is incorrect because a master services agreement generally defines the commercial relationship, but it does not automatically authorize attacks against every affiliate, subsidiary, or third party connected to the client. Testing authority must be explicit. Assuming implicit coverage is a frequent mistake in multi-entity environments, especially where ownership, governance, and liability differ between organizations.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam