ISTQB Mock App

Ethical Hacker

An ethical hacker is a security professional who is authorized to identify vulnerabilities in systems by simulating real-world attacks.

Official definition
ISTQB Official Glossary Definition
A security tester who follows the code of ethics of their organization.

(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)

View the complete ISTQB Glossary

What is Ethical Hacker?

Ethical hackers use the same techniques as malicious attackers but operate with permission to improve security rather than cause harm.

Authorized testing: All activities are performed with the owner's approval.

Security assessment: Ethical hackers identify weaknesses before attackers exploit them.

Reporting: Findings are documented with recommendations for remediation.

Real World Example

A regulated product team is preparing a release where Ethical hacker appears in reviews, test design conversations, or defect triage rather than as an isolated glossary word.

The risk is that the team treats Ethical hacker as interchangeable with nearby ISTQB terms. That makes test scope blurry and can lead to weak evidence for the release decision.

The tester anchors the discussion in the official definition, asks where the concept appears in the product, and designs examples that show the difference between Ethical hacker and similar ideas.

The page becomes useful in practice because Ethical hacker is connected to a specific testing decision, not memorized as a detached definition.

Practice Questions

Question 1

Which statement BEST describes Ethical hacker in the context of ISTQB terminology?

Question 2

A tester needs to explain Ethical hacker to a non‑technical stakeholder. Which approach is MOST appropriate?

Test your knowledge with real ISTQB-style questions

You’ve learned Ethical Hacker. Test your understanding with topic-specific questions in our Mock Exams.

Go to Mock Exams