312-50 exam dumps

312-50 practice question 4 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 4

Single answer▪ Hacking Methodologies and Frameworks

A security consulting firm is conducting an authorized penetration test for a healthcare provider. The client requires the team to follow a recognized testing framework, maintain a clear chain from intelligence gathering through exploitation and post-exploitation, and produce evidence that each activity was performed in a controlled and repeatable manner. During planning, the lead tester says the team should begin by exploiting an externally exposed VPN gateway immediately because it appears vulnerable. Another tester argues that the engagement should first follow the formal sequence defined in a standard penetration testing methodology so that scope, threat modeling, and attack paths are validated before exploitation begins. Which approach best aligns with established hacking methodologies and frameworks used in professional ethical hacking engagements?

  1. A

    Start exploitation immediately on the VPN gateway because finding a likely vulnerability early reduces testing time and is the most efficient use of the engagement window.

  2. B

    Follow a structured methodology such as PTES by progressing through pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting.

  3. C

    Use an incident response framework such as NIST SP 800-61 as the primary penetration testing methodology because it provides steps for handling security events during the assessment.

  4. D

    Skip threat modeling and vulnerability analysis if the target is internet-facing, because exposed systems are already approved for direct exploitation during a penetration test.

Show answer and explanation

Correct answer: B

Explanation

Professional ethical hacking engagements are expected to follow structured methodologies so activities are authorized, repeatable, and defensible. PTES is commonly referenced for penetration testing because it provides an end-to-end sequence from pre-engagement through reporting. Similarly, frameworks such as NIST SP 800-115 provide technical guidance for information security testing and assessment, reinforcing the importance of planning, discovery, analysis, and documentation before active exploitation. In this scenario, the best answer is to follow a formal methodology rather than jump directly into attacking an apparent target. That approach reduces operational risk, improves evidence quality, and ensures the engagement remains aligned with scope and client expectations.

  • A. Incorrect.

    This is incorrect because jumping directly to exploitation bypasses important methodology stages such as pre-engagement validation, rules of engagement, intelligence gathering, and vulnerability analysis. In a professional ethical hacking engagement, exploiting a system simply because it appears vulnerable can create unnecessary risk, scope violations, and weak documentation. A likely misconception is that speed is more valuable than process, but recognized frameworks emphasize controlled, repeatable testing.

  • B. Correct.

    This is correct. PTES (Penetration Testing Execution Standard) is a well-known framework that defines a logical flow: pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. This sequence supports disciplined testing, clear documentation, and defensible results. It also aligns with the client's requirement for a recognized methodology and controlled execution.

  • C. Incorrect.

    This is incorrect because NIST SP 800-61 is primarily an incident response guide, not a penetration testing execution framework. It is valuable for preparing for and handling security incidents, but it does not provide the full offensive testing lifecycle needed to plan and execute a penetration test. A candidate might choose this option because NIST publications are authoritative, but this specific document addresses a different security function.

  • D. Incorrect.

    This is incorrect because internet exposure does not remove the need for threat modeling, validation, and vulnerability analysis. Even when a system is in scope, testers should confirm attack paths, business impact, constraints, and safe test procedures before exploitation. This option reflects the misconception that scope approval alone justifies direct exploitation without following methodology.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam