Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam 312-50v12 topic 1 question 141 discussion

Actual exam question from ECCouncil's 312-50v12
Question #: 141
Topic #: 1
[All 312-50v12 Questions]

An organization suspects a persistent threat from a cybercriminal. They hire an ethical hacker, John, to evaluate their system security. John identifies several vulnerabilities and advises the organization on preventive measures. However, the organization has limited resources and opts to fix only the most severe vulnerability. Subsequently, a data breach occurs exploiting a different vulnerability. Which of the following statements best describes this scenario?

  • A. The organization is at fault because it did not fix all identified vulnerabilities.
  • B. Both the organization and John share responsibility because they did not adequately manage the vulnerabilities.
  • C. John is at fault because he did not emphasize the necessity of patching all vulnerabilities.
  • D. The organization is not at fault because they used their resources as per their understanding.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
abcd_qw
2 days, 13 hours ago
"because they did not adequately manage the vulnerabilities" -- how can they adequately manage the vulnerabilities ,somebody please say about that
upvoted 1 times
...
Spamerz
2 weeks, 3 days ago
Selected Answer: D
Organization used Risk Management. It means, they must first look to most severe vulnerability and go down, depending on resources. Both parties MUST NOT BLAME EACH OTHER, because it is not ethical. So, both - John and organization are right, just "sht happens".
upvoted 1 times
...
LordXander
1 month, 1 week ago
Selected Answer: B
AI says B, in practice it will be B (did the company implement a risk acceptance procedure and etc? well, they don't have the budget to fix so I doubt there's a acceptance process)
upvoted 1 times
...
qtygbapjpesdayazko
1 month, 1 week ago
Selected Answer: A
Keyword "opts to fix only the most severe vulnerability. Subsequently, a data breach occurs exploiting a different vulnerability." is A
upvoted 2 times
...
jettguo
1 month, 1 week ago
Selected Answer: A
I choose A, I think John do not have executive decisions on which vulnerability to fix, and he did his duty to present all the vulnerabilities he discovered.
upvoted 1 times
...
qwerty100
2 months ago
Selected Answer: B
B. Both the organization and John share responsibility because they did not adequately manage the vulnerabilities. The key is : a data breach occurs exploiting a different vulnerability
upvoted 2 times
...
anarchyeagle
2 months, 1 week ago
Selected Answer: A
I could not see how this answer is not A. It's clearly invoking Risk Management in which some risks have been mitigated while others are Accepted based on resource limitations. The only doubt in the question comes from the wording. Is the vulnerability that was exploited not identified by John, or was it an accepted vulnerability by the company? Either way, John was a contractor not an employee. It's the company's responsibility to understand that there is a risk in not seeking a second opinion. A is the only answer. The company is always responsible for their security without a contract transferring all risk to a third party company..
upvoted 3 times
brrbrr
2 months, 1 week ago
it is not specified that John is a contractor. It is indicated that John has been hired, so it could mean that it is an employee.
upvoted 1 times
...
...
brrbrr
2 months, 1 week ago
Selected Answer: B
B is the correct answer. Option A suggests that the organization is at fault because it did not fix all identified vulnerabilities. However, in the context of limited resources, organizations often need to prioritize and allocate their resources strategically. In the scenario described, the organization decided to fix the most severe vulnerability based on its understanding and resource limitations. While it's true that addressing all vulnerabilities would be ideal, practical constraints may prevent this. Therefore, placing the entire blame on the organization may not be fair. Option B is a more balanced choice, indicating that both the organization and John share responsibility. This acknowledges that the organization made a decision based on its constraints, but it also suggests that John, as the ethical hacker, has a role in emphasizing the importance of addressing all vulnerabilities and the potential risks associated with leaving some unpatched.
upvoted 1 times
...
barey
2 months, 2 weeks ago
Tricky, chat GPT4 says: In this scenario, both the organization and the ethical hacker, John, share responsibility. The organization chose to prioritize fixing only the most severe vulnerability due to limited resources, but it is their responsibility to make informed decisions based on the advice given by the ethical hacker. And Azure AI: A. The organization is at fault because it did not fix all identified vulnerabilities. but whan i aske why: he statement B can be seen as accurate because both the organization and John have roles in managing the vulnerabilities. John, as an ethical hacker, should emphasize the importance of addressing all identified vulnerabilities, LOL i put B on Exam
upvoted 2 times
duke_of_kamulu
2 months, 1 week ago
have done you exam if so how is it
upvoted 1 times
...
...
[Removed]
2 months, 2 weeks ago
Im not certain about the reliability of that information
upvoted 1 times
...
[Removed]
2 months, 2 weeks ago
Hey team can we double-check this response
upvoted 1 times
...
insaniunt
2 months, 2 weeks ago
Selected Answer: B
B. Both the organization and John share responsibility because they did not adequately manage the vulnerabilities.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...