A cybersecurity professional discovers a vulnerability in a public website. What is the ethical course of action?
- A.A. Exploit it and post the data online
- B.B. Practice responsible disclosure - report it privately to the organization, give them reasonable time to fix it, and do not exploit or publicize the vulnerability
- C.C. Sell the vulnerability to the highest bidder
- D.D. Ignore it completely
Why B is correct
Responsible (coordinated) disclosure means: report privately to the organization (often through security@company.com or bug bounty programs), provide technical details, give reasonable time to fix (typically 90 days), and only disclose publicly after the fix. Many companies have Vulnerability Disclosure Programs (VDP) or bug bounty programs (HackerOne, Bugcrowd) that reward ethical reporting.
Know someone studying for Security Fundamentals? Send them this one.