Show Answer


The correct answer is B.

OBJ-5.4: If an indicator of a previous compromise is found during a penetration test, the team should immediately inform the client’s trusted point of contact unless the scope of work states otherwise. The penetration testing team should have a direct communication path with the system owners or their trusted agents during an engagement. If the team discovers any security breaches, current hacking activity, extremely critical findings on a production server, or a production server becomes unresponsive during exploitation, then the team should stop what they are doing and contract their trusted point of contact within the organization to get further guidance. The trusted agents and communication paths should be determined when planning the engagement.

Hide Answer