A penetration test report rates a finding as Critical (CVSS 9.8) for an unauthenticated RCE vulnerability in the client's VPN appliance. The client's security manager argues the risk is 'Low' because 'we've never been hacked before.' How should the penetration tester respond?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because a penetration tester's professional obligation is to provide accurate risk assessments based on technical evidence, not client preference. An unauthenticated RCE on an internet-facing VPN gateway is objectively Critical; offering a controlled demonstration or threat intel provides objective evidence.
Full explanation below image
Full Explanation
B is correct because a penetration tester's professional obligation is to provide accurate risk assessments based on technical evidence, not client preference. An unauthenticated RCE on an internet-facing VPN gateway is objectively Critical; offering a controlled demonstration or threat intel provides objective evidence. A is wrong because adjusting severity to satisfy a client compromises the integrity of the assessment. C is wrong because omitting findings from a report constitutes professional misconduct. D is wrong because arbitrary compromise on severity without technical justification undermines the value of the assessment.