CISSP Practice Question – Security & Risk Management (Ethics)
While performing a security assessment for a client, you discover confidential information that suggests the client’s employees are engaging in activity that may be illegal but is unrelated to the scope of your engagement.
According to the ISC2 Code of Ethics, what is the BEST action for you to take?
A. Report the activity directly to law enforcement.
B. Inform your client’s senior management about the findings.
C. Document the evidence and keep it in case it’s needed later.
D. Ignore the activity since it is outside the scope of your contract.
4
17 comments
Vincent Primiani
7
CISSP Practice Question – Security & Risk Management (Ethics)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by