After completing a penetration test, the test team must handle the sensitive data and access obtained during testing. Which action is required at the conclusion of the engagement per professional standards?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because professional penetration test engagements require complete cleanup of all access created during testing (test accounts, backdoors, web shells) and secure destruction of all client data (credentials, sensitive files, network captures) per the Rules of Engagement to ensure no test artifacts remain that could be exploited or cause data protection issues. A is wrong because retaining client credentials and data beyond the engagement scope violates data protection principles and engagement terms.
Full explanation below image
Full Explanation
B is correct because professional penetration test engagements require complete cleanup of all access created during testing (test accounts, backdoors, web shells) and secure destruction of all client data (credentials, sensitive files, network captures) per the Rules of Engagement to ensure no test artifacts remain that could be exploited or cause data protection issues. A is wrong because retaining client credentials and data beyond the engagement scope violates data protection principles and engagement terms. C is wrong because storing client penetration test data including credentials on shared drives creates unnecessary data exposure risk. D is wrong because publicly disclosing vulnerabilities without client consent violates professional ethics, contractual obligations, and responsible disclosure principles.