Courseiva

CEH Introduction to Ethical Hacking Practice Question

An ethical hacker is hired to assess a hospital's network. The contract permits vulnerability discovery but explicitly forbids exploiting a flaw to access patient records. During testing, the hacker finds a SQL injection that would expose the patient database. Which action best reflects the ethical hacking principle of maintaining integrity and minimizing harm?

⚠ Common exam trap

The trap here is believing that fully exploiting a vulnerability is necessary to prove it, when a limited, non-destructive proof is sufficient and contractually required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the vulnerability with a non-destructive proof of concept, such as a boolean-based test, and report it without accessing patient data.

Ethical hacking requires proving risk without causing harm or exceeding authorization. A non-destructive proof of concept, such as a boolean-based injection test or retrieving only non-sensitive metadata, demonstrates the vulnerability exists while honoring the contract's restriction on patient data. This approach protects patients, preserves the client relationship, and still gives the hospital actionable evidence for remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Stop testing entirely and immediately terminate the engagement because a serious flaw was found.

    Why it's wrong here

    Abandoning the assessment wastes the client's investment and leaves other vulnerabilities undiscovered. Finding a serious flaw is expected during testing; the ethical response is to document it safely and continue within the agreed scope. Terminating without notifying the client through proper channels also delays remediation of the very risk discovered.

  • ✗

    Share the injection details with a public forum to pressure the hospital into patching quickly.

    Why it's wrong here

    Public disclosure of an unpatched vulnerability exposes the hospital and its patients to immediate attack by malicious actors. It also breaches the confidentiality terms of the engagement. Ethical hackers report findings privately to the client first, allowing time for remediation before any coordinated disclosure is discussed.

  • ✓

    Document the vulnerability with a non-destructive proof of concept, such as a boolean-based test, and report it without accessing patient data.

    Why this is correct

    Using a non-destructive proof, such as confirming a boolean condition or extracting only database version metadata, demonstrates the flaw while respecting the contract's prohibition on accessing patient records. This satisfies the goal of proving exploitability without causing harm. It aligns with the ethical principles of minimizing impact and staying within authorized scope.

  • ✗

    Exploit the injection fully and download a sample of patient records to prove the vulnerability is real.

    Why it's wrong here

    Downloading patient records violates the contract and data-protection obligations, causing real harm to patients whose privacy is compromised. Even with good intent, exfiltrating protected health information exceeds authorization and could trigger legal penalties. A proof of concept does not require accessing actual sensitive records, so this action is disproportionate and unethical.

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.