Which agreement did a pen tester breach by requesting a CVE without authorization?

A penetration tester requested, without express authorization, that a CVE number be assigned for a new vulnerability found on an internal client application. Which of the following did the penetration tester most likely breach?

  1. ROE
  2. SLA
  3. NDA Source Reference Answer
  4. SOW

Community Votes

C
52%
A
48%

52% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the difference between confidentiality agreements (NDA) and engagement boundaries (ROE) in penetration testing; the trap is choosing ROE because CVE disclosure is an unauthorized action, but the real breach is the unauthorized public disclosure of confidential client vulnerability information.

This PT0-002 question asks which agreement is breached when a penetration tester requests a CVE number for a client vulnerability without express authorization. Community consensus narrowly favors NDA because requesting a CVE involves disclosing confidential client information, though ROE is a close alternative.

ROE (Rules of Engagement) is the most common wrong answer, selected by 48% of voters. Testers choose it because requesting a CVE is an action outside the authorized scope of the engagement, but the primary violation is the unauthorized disclosure of confidential information, which is governed by the NDA.

Community Discussion (12 comments)

Big_Dre 👍 6 Selected: C
it socks being one of the first to comments u dont get the opinion of the others C. NDA (Non-Disclosure Agreement) The penetration tester most likely breached the NDA (Non-Disclosure Agreement) by requesting a CVE number without express authorization. NDA agreements typically prohibit the disclosure of sensitive information or findings without prior consent, and in this case, requesting a CVE number for a vulnerability found on an internal client application without authorization would likely violate the terms of the NDA.
Vslaugh 👍 1 Selected: A
The ROE defines the boundaries, permissions, and constraints for a penetration test, including what is allowed and not allowed during the engagement. Requesting a CVE number could be considered an action outside the agreed-upon scope unless specifically authorized.
BlackSkullz 👍 1 Selected: C
Requesting a CVE for a vulnerability discovered during a penetration test is disclosing private information exclusive to that test. This is a direct violation of any NDA that may of been signed to prohibit that information from being disclosed to the public
koala_lay 👍 2 Selected: A
A. ROE (Rules of Engagement) The Rules of Engagement typically outline the scope, authority, and protocols for conducting a penetration test, including how vulnerabilities should be reported and whether they can be publicly disclosed. Requesting a CVE number without express authorization suggests a violation of these agreed-upon rules.
Etc_Shadow28000 👍 4 Selected: A
A. ROE (Rules of Engagement): The Rules of Engagement document outlines the boundaries, scope, and specific permissions granted for the penetration test. Requesting a CVE number for a vulnerability found in an internal client application without express authorization likely breaches the rules regarding the scope of actions the tester is allowed to perform, especially actions that involve public disclosure or external entities. -------- C. NDA: An NDA ensures that confidential information is not disclosed to unauthorized parties. While this is relevant to the unauthorized disclosure of information, the primary concern here is the specific actions allowed during the penetration test, which falls under ROE.
isaphiltrick 👍 2 Selected: A
Given the nature of the action—requesting a CVE number for a vulnerability found in a client’s internal application without express authorization—the most directly relevant breach is: A. ROE (Rules of Engagement) The ROE would include what actions the penetration tester is authorized to perform, including how to handle vulnerability disclosures. By requesting a CVE number without authorization, the tester likely breached the agreed-upon rules and protocols defined in the ROE.
PhillyCheese 👍 2 Selected: C
The penetration tester most likely breached the Non-Disclosure Agreement (NDA). An NDA is a legal contract that prohibits disclosing confidential information without proper authorization. By requesting a CVE number without express consent, the tester violated the confidentiality obligations outlined in the NDA. It’s crucial to adhere to ethical standards and follow established procedures when handling vulnerabilities.
Sebatian20 👍 1 Selected: A
Poorly worded question but in a nutshell, the tester has submitted their findings to outside of the company to get a CVE allocated to their finding without approval from the company. This is a direct violation of a NDA
Jhonattan0032 👍 1
Definitely is A
PMann 👍 1 Selected: A
Seems to me they broke the rules of engagement and trying to cover with a found cve during vulnerability testing.
swiggharo 👍 3 Selected: C
C. NDA
aee9303 👍 2
To get a CVE, you have to disclose information on the vuln found. This means breaking the NDA of your contract. However, it can also be assumed that you did this without consulting anyone, which means it's against your ROE, but why are you submitting a report to get a CVE during a pentest? I feel like data retention policies/NDAs are the more likely answer.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The NDA (Non-Disclosure Agreement) is the correct answer because it is a legal contract that explicitly prohibits disclosing confidential information without authorization. By requesting a CVE number, the penetration tester publicly identifies a vulnerability found in a client's internal application, which constitutes disclosure of sensitive client data. As comment [1] points out, NDA agreements typically prohibit disclosure of sensitive findings without prior consent, and requesting a CVE is a public disclosure. Comment [5] reinforces that an NDA is a legal contract that prohibits disclosing confidential information without proper authorization, and requesting a CVE without express consent violates those confidentiality obligations.

Why the Other Options Are Wrong

A (ROE) is tempting because Rules of Engagement define the boundaries, scope, and permitted actions for a penetration test, but the ROE is more about the conduct of the test itself rather than the confidentiality of findings. While requesting a CVE may be outside the agreed ROE, the most direct breach is the NDA because the action involves disclosing private information to an external third party (CVE program). B (SLA) concerns service levels and performance expectations, which are not relevant to vulnerability disclosure. D (SOW) defines the work to be performed and deliverables, but does not govern the tester's post-engagement confidentiality obligations. As comment [6] notes, requesting a CVE requires disclosing information about the vulnerability, which breaks the NDA, and the ROE is more about consulting others during the test.

Community Comment Notes

The community is nearly split, with 52% choosing C and 48% choosing A, showing this is a genuinely tricky question. Comment [2] argues for ROE, stating that requesting a CVE without authorization breaches rules regarding scope, especially actions involving public disclosure. Comment [9] admits the question is poorly worded but concludes that submitting findings to an outside entity without company approval is a direct violation of an NDA. Comment [6] provides a nuanced view: while ROE could also be violated, the act of submitting a CVE report inherently breaks confidentiality, making NDA the likely intended answer. The key is to recognize that CVE assignment is a public disclosure event, and public disclosure of confidential findings is the hallmark of an NDA breach.

Official Reference

Exam Strategy

When a question involves unauthorized disclosure or publicizing vulnerabilities, focus on confidentiality agreements like NDAs rather than engagement scope. If the action is 'outside authorized actions,' ask what agreement specifically protects the client's confidential information—that is the agreement most likely breached.

Related Analysis

← Back to PT0-002 Study Guide