ACP Ethics & Professional Conduct 3 — Questions and Answers
Question 1: A client asks an Aruba-certified professional to bypass their organization's change management process to speed up a network upgrade. What should the professional do?
- Comply to satisfy the client and maintain the business relationship
- Explain the risks of bypassing change management and follow the established process (Correct answer)
- Bypass the process but document the changes retroactively
- Escalate immediately to executive leadership without consulting the client
Correct answer: Explain the risks of bypassing change management and follow the established process
Change management processes exist to reduce risk; bypassing them can lead to outages and is a violation of professional and organizational standards.
Question 2: An ACP professional working for a VAR discovers that a competitor is spreading false technical claims about Aruba products to customers. What is the appropriate professional response?
- Spread counter-claims about the competitor's products to level the playing field
- Correct the misinformation with accurate, factual technical information (Correct answer)
- Report the competitor to Aruba and let Aruba handle all customer communication
- Ignore the false claims to avoid appearing defensive
Correct answer: Correct the misinformation with accurate, factual technical information
Responding with accurate technical facts is the ethical and professional approach rather than retaliating with counter-misinformation.
Question 3: During a penetration test authorized only for VLAN 10, an ACP professional discovers a critical vulnerability on VLAN 20. What should they do?
- Exploit the VLAN 20 vulnerability to demonstrate its severity
- Document the finding and immediately notify the client without exploiting the out-of-scope resource (Correct answer)
- Ignore the finding because VLAN 20 is outside the authorized scope
- Expand the scope unilaterally to fully assess the vulnerability
Correct answer: Document the finding and immediately notify the client without exploiting the out-of-scope resource
Ethical penetration testers must stay within authorized scope and report out-of-scope findings to the client without exploiting them.
Question 4: A certification holder is asked by their employer to participate in fraudulent testing for a client acceptance sign-off. What is the correct ethical action?
- Participate under protest and document disagreement internally
- Refuse to participate and report the issue through appropriate ethics or legal channels (Correct answer)
- Perform only the fraudulent steps that do not directly falsify data
- Anonymously tip off the client about the fraud without officially refusing
Correct answer: Refuse to participate and report the issue through appropriate ethics or legal channels
Participating in fraudulent testing violates professional ethics codes and potentially laws; refusal and proper reporting are the required responses.
Question 5: Which of the following best describes a professional's obligation when they become aware that their ACP certification has lapsed?
- Continue using the ACP credential until a client or employer asks for proof of currency
- Immediately stop representing yourself as ACP-certified and pursue renewal (Correct answer)
- Use the credential only for internal projects until renewal is complete
- Notify only future clients, not current ones, about the lapse
Correct answer: Immediately stop representing yourself as ACP-certified and pursue renewal
Representing yourself as holding a lapsed certification is misrepresentation; the credential must be renewed before it can be cited.
Question 6: A network professional inherits a poorly documented legacy network from a former employee. The fastest fix involves a configuration that violates the client's stated security policy. What should they do?
- Apply the quick fix since it is a legacy issue predating the current team
- Implement a compliant solution even if it takes longer, and document the legacy issues found (Correct answer)
- Apply the quick fix and update the security policy retroactively to match
- Delay all work until the legacy network is fully documented
Correct answer: Implement a compliant solution even if it takes longer, and document the legacy issues found
Security policy compliance is non-negotiable; the professional must implement compliant solutions and document inherited issues for proper remediation.
Question 7: An Aruba-certified professional uses GPL-licensed open-source code in a client deliverable without including the required license notice. This primarily violates which professional obligation?
- The obligation to maintain network uptime above SLA thresholds
- The obligation to respect intellectual property rights and license terms (Correct answer)
- The obligation to obtain client approval before using third-party tools
- The obligation to disclose all software costs to the client
Correct answer: The obligation to respect intellectual property rights and license terms
GPL licenses require attribution and often source code disclosure; ignoring these terms violates intellectual property law and professional ethics.
A client asks an Aruba-certified professional to bypass their organization's change management process to speed up a network upgrade.
What should the professional do?