Under the Computer Fraud and Abuse Act (CFAA), what distinguishes authorized penetration testing from criminal hacking?
-
A
The tools used during the test
-
B
Written permission from the system owner
-
C
The time of day the test is conducted
-
D
Whether vulnerabilities are actually exploited