A penetration tester successfully gains domain administrator privileges during an internal test. What should be the tester's immediate next step?
-
A
Continue exploiting other systems to demonstrate full domain compromise
-
B
Document the finding, notify the client per the rules of engagement, and await guidance
-
C
Delete evidence of the compromise to test incident response
-
D
Create a persistent backdoor to demonstrate long-term risk