Which agreement did a pen tester breach by requesting a CVE without authorization?
A penetration tester requested, without express authorization, that a CVE number be assigned for a new vulnerability found on an internal client application. Which of the following did the penetration tester most likely breach?
Community Votes
52% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the difference between confidentiality agreements (NDA) and engagement boundaries (ROE) in penetration testing; the trap is choosing ROE because CVE disclosure is an unauthorized action, but the real breach is the unauthorized public disclosure of confidential client vulnerability information.
This PT0-002 question asks which agreement is breached when a penetration tester requests a CVE number for a client vulnerability without express authorization. Community consensus narrowly favors NDA because requesting a CVE involves disclosing confidential client information, though ROE is a close alternative.
ROE (Rules of Engagement) is the most common wrong answer, selected by 48% of voters. Testers choose it because requesting a CVE is an action outside the authorized scope of the engagement, but the primary violation is the unauthorized disclosure of confidential information, which is governed by the NDA.
Community Discussion (12 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The NDA (Non-Disclosure Agreement) is the correct answer because it is a legal contract that explicitly prohibits disclosing confidential information without authorization. By requesting a CVE number, the penetration tester publicly identifies a vulnerability found in a client's internal application, which constitutes disclosure of sensitive client data. As comment [1] points out, NDA agreements typically prohibit disclosure of sensitive findings without prior consent, and requesting a CVE is a public disclosure. Comment [5] reinforces that an NDA is a legal contract that prohibits disclosing confidential information without proper authorization, and requesting a CVE without express consent violates those confidentiality obligations.
Why the Other Options Are Wrong
A (ROE) is tempting because Rules of Engagement define the boundaries, scope, and permitted actions for a penetration test, but the ROE is more about the conduct of the test itself rather than the confidentiality of findings. While requesting a CVE may be outside the agreed ROE, the most direct breach is the NDA because the action involves disclosing private information to an external third party (CVE program). B (SLA) concerns service levels and performance expectations, which are not relevant to vulnerability disclosure. D (SOW) defines the work to be performed and deliverables, but does not govern the tester's post-engagement confidentiality obligations. As comment [6] notes, requesting a CVE requires disclosing information about the vulnerability, which breaks the NDA, and the ROE is more about consulting others during the test.
Community Comment Notes
The community is nearly split, with 52% choosing C and 48% choosing A, showing this is a genuinely tricky question. Comment [2] argues for ROE, stating that requesting a CVE without authorization breaches rules regarding scope, especially actions involving public disclosure. Comment [9] admits the question is poorly worded but concludes that submitting findings to an outside entity without company approval is a direct violation of an NDA. Comment [6] provides a nuanced view: while ROE could also be violated, the act of submitting a CVE report inherently breaks confidentiality, making NDA the likely intended answer. The key is to recognize that CVE assignment is a public disclosure event, and public disclosure of confidential findings is the hallmark of an NDA breach.
Official Reference
Exam Strategy
When a question involves unauthorized disclosure or publicizing vulnerabilities, focus on confidentiality agreements like NDAs rather than engagement scope. If the action is 'outside authorized actions,' ask what agreement specifically protects the client's confidential information—that is the agreement most likely breached.