In an unprotected network file repository a penetration test - CompTIA Pentest+ PT0-003

Question

In an unprotected network file repository, a penetration tester discovers a text file containing usernames and passwords in cleartext and a spreadsheet containing data for 50 employees, including full names, roles, and serial numbers. The tester realizes some of the passwords in the text file follow the format: <name- serial_number>.
Which of the following would be the best action for the tester to take NEXT with this information?

Answers
  1. correct
Explanation

Correct Answer: D. Document the unprotected file repository as a finding in the penetration-testing report.

As a penetration tester, your primary responsibility is to identify vulnerabilities and report them. Since you found cleartext credentials and employee data in an unprotected file repository, the first action should be to document this security flaw as a finding in the penetration test report.

  • The file repository is unprotected, meaning anyone with access can view or steal the credentials and employee data.
  • The password format (<name-serial_number>) indicates a weak, predictable pattern, which further increases the risk of credential compromise.
  • Reporting this as a finding ensures that the organization addresses and remediates the issue.

Why the Other Options Are Incorrect:

Create a custom password dictionary as preparation for password spray testing.

  •  While this could be useful in an active attack scenario, it is not the most immediate or ethical next step.

  • Risk: The goal of a penetration test is to assess security and report weaknesses, not to actively exploit every flaw unless explicitly authorized.

Before attempting a password spray, you should report the weak credential storage issue first.

Recommend using a password manager/vault instead of text files to store passwords securely.

  •  While using a password manager is a good security recommendation, it is not the first action the tester should take.

  • Risk: Making recommendations comes after documenting findings in the report.

Before making recommendations, document the issue as a security risk first.

Recommend configuring password complexity rules in all the systems and applications.

  • While enforcing strong password policies is important, the primary issue here is the unprotected storage of credentials.

  • Risk: Even with strong password policies, storing credentials in plaintext is a severe security risk.

Password complexity alone does not fix the issue of unprotected credentials.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered