CEH Introduction to Ethical Hacking Practice Question
An ethical hacker is hired to assess a hospital's network. The contract permits vulnerability discovery but explicitly forbids exploiting a flaw to access patient records. During testing, the hacker finds a SQL injection that would expose the patient database. Which action best reflects the ethical hacking principle of maintaining integrity and minimizing harm?
⚠ Common exam trap
The trap here is believing that fully exploiting a vulnerability is necessary to prove it, when a limited, non-destructive proof is sufficient and contractually required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the vulnerability with a non-destructive proof of concept, such as a boolean-based test, and report it without accessing patient data.
Ethical hacking requires proving risk without causing harm or exceeding authorization. A non-destructive proof of concept, such as a boolean-based injection test or retrieving only non-sensitive metadata, demonstrates the vulnerability exists while honoring the contract's restriction on patient data. This approach protects patients, preserves the client relationship, and still gives the hospital actionable evidence for remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stop testing entirely and immediately terminate the engagement because a serious flaw was found.
Why it's wrong here
Abandoning the assessment wastes the client's investment and leaves other vulnerabilities undiscovered. Finding a serious flaw is expected during testing; the ethical response is to document it safely and continue within the agreed scope. Terminating without notifying the client through proper channels also delays remediation of the very risk discovered.
- ✗
Share the injection details with a public forum to pressure the hospital into patching quickly.
Why it's wrong here
Public disclosure of an unpatched vulnerability exposes the hospital and its patients to immediate attack by malicious actors. It also breaches the confidentiality terms of the engagement. Ethical hackers report findings privately to the client first, allowing time for remediation before any coordinated disclosure is discussed.
- ✓
Document the vulnerability with a non-destructive proof of concept, such as a boolean-based test, and report it without accessing patient data.
Why this is correct
Using a non-destructive proof, such as confirming a boolean condition or extracting only database version metadata, demonstrates the flaw while respecting the contract's prohibition on accessing patient records. This satisfies the goal of proving exploitability without causing harm. It aligns with the ethical principles of minimizing impact and staying within authorized scope.
- ✗
Exploit the injection fully and download a sample of patient records to prove the vulnerability is real.
Why it's wrong here
Downloading patient records violates the contract and data-protection obligations, causing real harm to patients whose privacy is compromised. Even with good intent, exfiltrating protected health information exceeds authorization and could trigger legal penalties. A proof of concept does not require accessing actual sensitive records, so this action is disproportionate and unethical.
Go deeper
Related to this question
Learn chapter
SQL Injection
Key term
Evil Twin Attack
An evil twin attack is a type of wireless hacking where a fake Wi-Fi access point mimics a legitimate one to trick users into connecting, allowing the attacker to intercept traffic and steal data.
Key term
SQL injection
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often to read, modify, or destroy data.
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.