ペネトレーション テスターが、明示的な許可なしに、内部クライアント アプリケーションで見つかった新しい脆弱性に対して CVE 番号を割り当てるよう要求しました。ペネトレーションテスターが違反した可能性が最も高いのは次のうちどれですか?
正解:A
ROE stands for Rules of Engagement, which are the guidelines and limitations that define the scope, objectives, and methods of a penetration testing engagement. ROE should be agreed upon by both the client and the tester before the testing begins, and they should include the authorization to perform certain actions, such as requesting CVE numbers, disclosing vulnerabilities, or exploiting systems. By requesting a CVE number without express authorization, the penetration tester most likely breached the ROE and violated the client's trust and expectations. References:
*The Official CompTIA PenTest+ Study Guide (Exam PT0-002), Chapter 1: Planning and Scoping Penetration Tests, page 23-24.
*CVE - CVE1
*NDA, MSA, SOW and SLA. Confidentiality agreements when you outsource QA