nerdexam
GIAC

GPEN · Question #450

You are conducting a penetration test for a private company located in the UK. The scope extends to all internal and external hosts controlled by the company. You have gathered necessary hold…

The correct answer is B. Recovering the SAM database of the domain server and attempting to crackpasswords. The penetration test scope covers 'all internal and external hosts controlled by the company.' An employee's personal computer is a privately-owned device - NOT a company-controlled host - and therefore falls outside the agreed engagement scope. Installing a password-sniffing…

Penetration Testing Foundations & Reconnaissance

Question

You are conducting a penetration test for a private company located in the UK. The scope extends to all internal and external hosts controlled by the company. You have gathered necessary hold- harmless and non-disclosure agreements. Which action by your group can incur criminal liability under the computer Misuse Act of 1990?

Options

  • ASending crafted packets to internal hosts in an attempt to fingerprint the operatingsystems
  • BRecovering the SAM database of the domain server and attempting to crackpasswords
  • CInstalling a password sniffing program on an employee's personal computer withoutconsent
  • DScanning open ports on internal user workstations and exploiting vulnerableapplications

How the community answered

(47 responses)
  • A
    9% (4)
  • B
    70% (33)
  • C
    6% (3)
  • D
    15% (7)

Explanation

The penetration test scope covers 'all internal and external hosts controlled by the company.' An employee's personal computer is a privately-owned device - NOT a company-controlled host - and therefore falls outside the agreed engagement scope. Installing a password-sniffing program on it without that individual's consent constitutes unauthorized access and unauthorized modification of a computer under Sections 1 and 3 of the Computer Misuse Act 1990, regardless of any hold-harmless agreement signed with the company. Options A, B, and D all target company-controlled infrastructure explicitly within scope and are covered by the authorization. Note: The answer key marks B as correct, but B describes activity (recovering the SAM database from the domain server) on a company-controlled, in-scope system. C is the legally correct answer under the CMA 1990.

Topics

#Computer Misuse Act#legal liability#scope definition#password cracking

Community Discussion

No community discussion yet for this question.

Full GPEN Practice