正解:C
In CEH v13 Information Security and Ethical Hacking Overview, a penetration tester is defined as a trusted, authorized security professional hired to simulate real-world attacks in order to identify and exploit vulnerabilities with explicit permission.
The primary objectives of a penetration tester are:
* Identify weaknesses in systems, networks, and applications
* Demonstrate real-world impact of vulnerabilities
* Help organizations improve their security posture
Unlike malicious hackers (Option A) or malware authors (Options B and D), penetration testers operate under strict legal and ethical guidelines, following scopes of engagement and reporting findings responsibly.
CEH v13 emphasizes that penetration testing is proactive defense, not crime. Therefore, Option C accurately defines the role.