Courseiva
hardMultiple ChoiceObjective-mapped

CISSP Practice Question: During a penetration test, the tester gains…

During a penetration test, the tester gains access to a server and finds sensitive customer data. What should the tester do next?

⚠ Common exam trap

Candidates often confuse the goal of demonstrating risk (which is valid in a controlled lab) with the ethical obligation to protect live data; the CISSP exam emphasizes that a tester must never exfiltrate or alter production data, even to prove a point.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Report the finding immediately and secure the data

The tester's primary responsibility is to protect sensitive data and minimize risk. Upon discovering PII or other regulated data, the tester must immediately report the finding to the client and secure the data (e.g., by isolating the server or encrypting the data in place) to prevent unauthorized access or exposure. This aligns with the ethical hacking code of conduct and the CISSP principle of 'do no harm'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Exfiltrate the data to demonstrate the risk

    Why it's wrong here

    Exfiltrating sensitive data, even to demonstrate risk, constitutes an unauthorized data breach and falls outside the ethical and legal boundaries of a penetration test. Unless explicitly defined within the Statement of Work (SOW) with specific, controlled conditions (e.g., dummy data), such actions violate privacy regulations, client trust, and could lead to severe legal repercussions for both the tester and the client organization. The purpose of a pen test is to identify vulnerabilities, not to cause actual harm or unauthorized data movement.

  • Delete the data to prevent exposure

    Why it's wrong here

    Deleting data, even with the intention of preventing further exposure, is a highly destructive and unethical action for a penetration tester. This act destroys critical forensic evidence necessary for the client's incident response team to understand the attack vector, scope of compromise, and implement effective remediation. Furthermore, it violates the principle of non-disruption and could lead to significant data loss for the client, exceeding the authorized scope and potentially causing more harm than the original vulnerability.

  • Continue testing to find more vulnerabilities

    Why it's wrong here

    Continuing to test for more vulnerabilities after gaining access to sensitive data is a misprioritization and significantly increases the risk to the organization. Once a critical compromise like sensitive data access is achieved, the immediate focus must shift from discovery to containment and reporting. Further probing could inadvertently corrupt data, trigger security alerts, or broaden the exposure of the sensitive information, escalating the incident rather than helping to mitigate it.

  • Report the finding immediately and secure the data

    Why this is correct

    Immediately reporting the finding and coordinating to secure the data is the paramount ethical and professional responsibility of a penetration tester upon discovering sensitive data access. This action adheres to responsible disclosure principles, enabling the client's incident response team to swiftly contain the breach, conduct forensics, and remediate the vulnerability before further damage occurs. Securing the data, often in collaboration with the client, might involve isolating the compromised system or revoking the unauthorized access path, ensuring the integrity and confidentiality of the information.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.