GPEN GIAC Penetration Tester Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

During a penetration test of a retail company\'s e-commerce platform, a security consultant identifies a critical SQL injection vulnerability. This vulnerability allows access to a database containing customer records, including names, addresses, and purchase histories, all of which are classified as personal data under the General Data Protection Regulation (GDPR). The consultant, concerned that this data could be exploited by malicious actors if the vulnerability were to be discovered and exploited by them, decides to proactively anonymize all customer records within the database through the identified vulnerability before reporting the findings. What is the most significant ethical and legal implication of the consultant\'s decision to anonymize the data?

The consultant has engaged in unauthorized processing and modification of personal data, violating GDPR principles of lawfulness, fairness, transparency, and purpose limitation, and potentially creating a new data breach incident.
The consultant has demonstrated excellent initiative and problem-solving skills by mitigating a potential data leak, thereby exceeding the scope of the engagement and protecting the client from future harm.
The consultant has inadvertently strengthened the client's data security posture by implementing an anonymization technique that the client had not yet deployed, thus fulfilling a higher duty of care.
The consultant has prioritized client safety over strict adherence to the penetration testing scope, which is a common and acceptable practice in advanced security assessments to preemptively address critical risks.

About the GPEN GIAC Penetration Tester Certification

These free practice questions are designed to help you assess your readiness for the GPEN GIAC Penetration Tester exam by Other. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.