A penetration tester identifies an unpatched, legacy payment processing server residing on the same subnet as the primary target. The payment server is explicitly excluded from the engagement scope. What is the correct action?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- AEven a non-intrusive scan is active testing of a system the client excluded, which breaches the agreed scope.
- BManual exploitation of an out-of-scope system is unauthorized access, however careful the tester is.
- CSending any payload to an excluded server violates the engagement terms and may disrupt payment processing.
- DCorrect: the tester must leave excluded systems alone and report the observation to the client, who can decide whether to authorize testing.