Professional Standards & Ethics Flashcards
7 cards from real GCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Professional Standards & Ethics flashcards as text
A GCP professional discovers a zero-day vulnerability in a widely used open-source library. What is the ethical course of action?
Answer: Follow responsible disclosure practices and notify the maintainers privately
Responsible disclosure requires privately notifying the affected vendor or maintainer first, giving them time to patch before public disclosure.
Under the Computer Fraud and Abuse Act (CFAA), which activity constitutes unauthorized access?
Answer: Accessing systems or data beyond the scope of your granted permissions
The CFAA prohibits accessing computer systems in ways that exceed authorized permissions, regardless of intent.
During a penetration test, you discover evidence of a prior unauthorized intrusion by an external attacker. What is the correct professional response?
Answer: Immediately stop, preserve evidence, and notify the client
Discovering a real breach requires halting the engagement to protect evidence integrity and notifying the client so they can activate incident response.
What is the professional obligation when a cloud engineer suspects a colleague is accessing client data without authorization?
Answer: Report the suspected misconduct through appropriate internal or external channels
Suspected misconduct involving unauthorized data access must be reported through proper channels; self-investigation or inaction is inappropriate.
Which activity remains prohibited during a penetration test even when a signed scope agreement is in place?
Answer: Accessing systems explicitly listed as out-of-scope
Out-of-scope systems are never authorized regardless of what is discovered during the engagement; the scope agreement defines hard boundaries.
A cloud engineer accidentally gains read access to another customer's data due to a provider misconfiguration. What should they do?
Answer: Immediately report it to the cloud provider and cease all access
Accessing another customer's data — even accidentally — must be stopped immediately and reported to the provider for proper incident handling.
Which security principle holds that controls should be proportional to the value of the asset being protected and the cost of protection?
Answer: Risk-based security
Risk-based security prioritizes protection efforts and spending based on asset value, threat likelihood, and the cost of controls.