During a vulnerability assessment, Nessus identifies a host as vulnerable to MS17-010 (EternalBlue). The rules of engagement for this engagement specify 'vulnerability assessment only — no exploitation.' What is the correct action?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because rules of engagement define the legal and contractual boundary of the assessment; a vulnerability assessment scope prohibits exploitation. Scanner-identified findings with corroborating evidence (OS version, patch level) are sufficient to report with high confidence.
Full explanation below image
Full Explanation
B is correct because rules of engagement define the legal and contractual boundary of the assessment; a vulnerability assessment scope prohibits exploitation. Scanner-identified findings with corroborating evidence (OS version, patch level) are sufficient to report with high confidence. A is wrong because exploitation violates the defined rules of engagement regardless of evidentiary value. C is wrong because MS17-010 is well-characterized and scanner detection has high confidence; dismissing it would be negligent. D is wrong because concealing exploitation from the report while performing it violates professional ethics and the terms of the engagement.