What should a CREST tester do immediately upon discovering evidence of an active criminal intrusion during an authorized engagement?
-
A
Continue testing and document findings in the final report
-
B
Stop testing and escalate to the client's incident response contact immediately
-
C
Attempt to remove the attacker from the system
-
D
Post findings to a public disclosure platform