An ethical hacker is hired to assess a hospital's network. The contract permits vulnerability discovery but explicitly forbids exploiting a flaw to access patient records. During testing, the hacker finds a SQL injection that would expose the patient database. Which action best reflects the ethical hacking principle of maintaining integrity and minimizing harm?
Using a non-destructive proof, such as confirming a boolean condition or extracting only database version metadata, demonstrates the flaw while respecting the contract's prohibition on accessing patient records. This satisfies the goal of proving exploitability without causing harm. It aligns with the ethical principles of minimizing impact and staying within authorized scope.
Why this answer
Ethical hacking requires proving risk without causing harm or exceeding authorization. A non-destructive proof of concept, such as a boolean-based injection test or retrieving only non-sensitive metadata, demonstrates the vulnerability exists while honoring the contract's restriction on patient data. This approach protects patients, preserves the client relationship, and still gives the hospital actionable evidence for remediation.
Exam trap
The trap here is believing that fully exploiting a vulnerability is necessary to prove it, when a limited, non-destructive proof is sufficient and contractually required.