CASE Professional Ethics & Standards 2 — Questions and Answers
Question 1: A security engineer discovers a zero-day vulnerability in a client's production system during a penetration test. The client's contract specifies findings must be reported within 30 days. What is the MOST ethical course of action?
- Wait 30 days as specified in the contract
- Report the vulnerability to the client immediately due to its severity (Correct answer)
- Publish the vulnerability publicly to pressure the client
- Exploit the vulnerability further to document its full impact
Correct answer: Report the vulnerability to the client immediately due to its severity
Critical vulnerabilities should be reported immediately to the client regardless of contract timelines to prevent potential harm.
Question 2: Under the ISC2 Code of Ethics, which canon takes the HIGHEST priority when canons conflict?
- Act honorably, honestly, justly, responsibly, and legally
- Provide diligent and competent service to principals
- Protect society, the common good, necessary public trust and confidence (Correct answer)
- Advance and protect the profession
Correct answer: Protect society, the common good, necessary public trust and confidence
ISC2's Code of Ethics lists protecting society as the first and highest-priority canon.
Question 3: A CASE professional is asked by their employer to implement a security control they believe violates user privacy rights. After raising concerns internally with no resolution, the MOST appropriate next step is to:
- Implement the control as directed by the employer
- Immediately resign without further action
- Escalate through appropriate channels such as legal counsel or a regulatory body (Correct answer)
- Publicly disclose the employer's practices on social media
Correct answer: Escalate through appropriate channels such as legal counsel or a regulatory body
When internal escalation fails, professionals should use legitimate channels such as legal or regulatory bodies rather than public disclosure or silent compliance.
Question 4: Which principle is MOST directly violated when a security professional accepts gifts from a vendor whose product they are evaluating for their organization?
- Confidentiality
- Non-repudiation
- Conflict of interest avoidance (Correct answer)
- Least privilege
Correct answer: Conflict of interest avoidance
Accepting gifts from a vendor being evaluated creates a conflict of interest that compromises objectivity.
Question 5: An application security engineer identifies that a colleague is deliberately injecting vulnerabilities into code to appear more valuable during remediation. This behavior MOST directly violates which ethical principle?
- Advance and protect the profession
- Provide diligent service to principals
- Act honorably and honestly (Correct answer)
- Maintain competence in the field
Correct answer: Act honorably and honestly
Deliberately creating vulnerabilities for personal gain is a fundamentally dishonest and unethical act.
Question 6: A security professional learns of a data breach at a former employer where they had access to sensitive systems. They are no longer employed there. Their BEST course of action is to:
- Do nothing, as they no longer work there
- Notify the former employer anonymously
- Contact the appropriate regulatory authority if personal data is at risk (Correct answer)
- Attempt to help remediate the breach using their old credentials
Correct answer: Contact the appropriate regulatory authority if personal data is at risk
Professionals retain ethical obligations to protect the public and may notify regulators when personal data is at risk, even after leaving an organization.
Question 7: When performing a security code review under a non-disclosure agreement (NDA), a CASE professional discovers evidence of fraud unrelated to the security engagement. What should the professional do FIRST?
- Disclose the fraud publicly to warn others
- Ignore it as it is outside the scope of the engagement
- Consult legal counsel to understand obligations before taking action (Correct answer)
- Include the finding in the security report without mentioning it to anyone else
Correct answer: Consult legal counsel to understand obligations before taking action
Legal counsel can clarify whether mandatory reporting laws override NDA obligations before the professional takes action.
A security engineer discovers a zero-day vulnerability in a client's production system during a penetration test.
The client's contract specifies findings must be reported within 30 days.
What is the MOST ethical course of action?