nerdexam
GIAC

GPEN · Question #422

You are conducting a penetration test for a private contractor located in Singapore. The scope extends to all internal hosts controlled by the company, you have gathered necessary hold- harmless and…

The correct answer is D. Cracking password hashes on the corporate domain server. Under Singapore's Computer Misuse Act (CMA) Chapter 50A, the hold-harmless agreement is with the contracting company - it can authorize testing of company-owned systems, but it cannot extend authorization to individual employees' personal credentials. Cracking password hashes…

Penetration Testing Foundations & Reconnaissance

Question

You are conducting a penetration test for a private contractor located in Singapore. The scope extends to all internal hosts controlled by the company, you have gathered necessary hold- harmless and nondisclosure agreements. Which action by your group can incur criminal liability under Chapter 50a, Computer Misuse Act?

Options

  • AExploiting vulnerable web services on internal hosts
  • BAttempts at social engineering employees via telephone calls
  • CTesting denial-of-service tolerance of the communications provider
  • DCracking password hashes on the corporate domain server

How the community answered

(27 responses)
  • A
    19% (5)
  • B
    4% (1)
  • C
    7% (2)
  • D
    70% (19)

Explanation

Under Singapore's Computer Misuse Act (CMA) Chapter 50A, the hold-harmless agreement is with the contracting company - it can authorize testing of company-owned systems, but it cannot extend authorization to individual employees' personal credentials. Cracking password hashes on the corporate domain server reveals individual users' plaintext passwords, which are personal data belonging to those individuals, not just the company. Exposing those credentials may constitute unauthorized access to protected computer material beyond what the company alone can legally authorize, potentially incurring criminal liability under the CMA even within a signed engagement. Actions A, B, and D against internal company hosts are covered by the engagement scope, whereas D specifically crosses into accessing individual users' protected credential data that the company has no right to waive on their behalf.

Topics

#Computer Misuse Act#Singapore law#legal liability#scope compliance

Community Discussion

No community discussion yet for this question.

Full GPEN Practice