A Cognizant consultant discovers that a client's system contains a critical security vulnerability that was not part of the original project scope. What is the most ethical course of action?
-
A
Ignore it since it is outside the project scope
-
B
Immediately report it to the client stakeholders and document it in writing
-
C
Fix it quietly without informing anyone to avoid scope conflict
-
D
Exploit the vulnerability to demonstrate its severity to the client