Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementHard
A security team is conducting a penetration test on a new e-commerce platform. During the post-exploitation phase, the tester successfully establishes a persistent backdoor on a server and extracts sensitive customer data. What is the MOST critical next step the penetration tester should take before completing the engagement, according to ethical hacking principles?
- ARemove all persistence mechanisms and artifacts from the compromised system.
- BRun a vulnerability scan to identify additional weaknesses.
- CInform the client immediately about the data breach.
- DDocument all findings, including the backdoor and extracted data.
Show answer & explanationAnswer & explanation
Correct answer: A. Remove all persistence mechanisms and artifacts from the compromised system.
Ethical hacking principles dictate that all changes made during a penetration test, including persistence mechanisms and other artifacts, must be thoroughly cleaned up to restore the system to its pre-test state and prevent any unintended access by others.
Why the other options are wrong
- B. Running another scan is part of a different phase or a separate activity, not the immediate priority post-exploitation cleanup.
- C. While important, client notification is usually part of reporting, and removal of artifacts is a more immediate ethical responsibility to the client's security.
- D. Documentation is essential, but removal of artifacts is a more critical immediate action for ethical reasons.
Post-Engagement Cleanup
The final phase of a penetration test where all tools, backdoors, and modifications made by the tester are removed from the target systems.
- Ensures system integrity and security post-test.
- Prevents unauthorized access through tester-created artifacts.
- A crucial ethical responsibility of the penetration tester.
Memory trick: After the 'attack', you must 'clean up' and report.