Question 1 of 30
Operational review demonstrates that a financial institution has engaged your firm to conduct a penetration test. The client has explicitly stated that the primary objective is to identify vulnerabilities that could lead to unauthorized access or data exfiltration, but with an absolute mandate to avoid any disruption to live customer-facing services during business hours. Given these constraints, which of the following approaches best aligns with professional ethical standards and client requirements?
Begin with comprehensive passive reconnaissance and vulnerability scanning to identify potential weaknesses, followed by a phased, authorized approach to controlled exploitation of high-risk findings during agreed-upon maintenance windows.
Immediately initiate aggressive exploitation of all identified vulnerabilities to simulate a real-world attack scenario, prioritizing speed and breadth of testing.
Conduct a full-scope, intrusive penetration test that mimics advanced persistent threats, without seeking specific client approval for each exploitation technique.
Limit testing exclusively to passive reconnaissance and vulnerability scanning, ensuring no active system interaction, even if it means not validating the exploitability of certain findings.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free