Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementHard

A security team is conducting a penetration test on a new e-commerce platform. During the post-exploitation phase, the tester successfully establishes a persistent backdoor on a server and extracts sensitive customer data. What is the MOST critical next step the penetration tester should take before completing the engagement, according to ethical hacking principles?

  1. ARemove all persistence mechanisms and artifacts from the compromised system.
  2. BRun a vulnerability scan to identify additional weaknesses.
  3. CInform the client immediately about the data breach.
  4. DDocument all findings, including the backdoor and extracted data.
Show answer & explanation

Correct answer: A. Remove all persistence mechanisms and artifacts from the compromised system.

Ethical hacking principles dictate that all changes made during a penetration test, including persistence mechanisms and other artifacts, must be thoroughly cleaned up to restore the system to its pre-test state and prevent any unintended access by others.

Why the other options are wrong

  • B. Running another scan is part of a different phase or a separate activity, not the immediate priority post-exploitation cleanup.
  • C. While important, client notification is usually part of reporting, and removal of artifacts is a more immediate ethical responsibility to the client's security.
  • D. Documentation is essential, but removal of artifacts is a more critical immediate action for ethical reasons.

Post-Engagement Cleanup

The final phase of a penetration test where all tools, backdoors, and modifications made by the tester are removed from the target systems.

  • Ensures system integrity and security post-test.
  • Prevents unauthorized access through tester-created artifacts.
  • A crucial ethical responsibility of the penetration tester.

Memory trick: After the 'attack', you must 'clean up' and report.

More Vulnerability Management questions