ペネトレーションテスターは、企業のネットワークの脆弱性を特定し、それを悪用しようと試みることで、合法的にセキュリティを評価するために雇用されます。これはどのようなタイプのハッカーでしょうか?
正解:D
CEH v13 defines a white hat hacker as a security professional with explicit authorization to perform penetration testing, vulnerability assessments, and exploitation attempts within legal and contractual boundaries. Their objective is to strengthen security, not compromise it. White hats follow structured methodologies, document findings, and provide remediation recommendations. A black hat (Option A) acts maliciously and without permission. A grey hat (Option B) operates without authorization but without harmful intent, which is not compliant with corporate penetration testing procedures. Script kiddies (Option C) rely on pre-built tools without deep knowledge and are not employed for legitimate engagements.
Therefore, the individual described is a white hat, operating under legal and ethical guidelines with organizational consent.