exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 207 discussion

Actual exam question from CompTIA's PT0-002
Question #: 207
Topic #: 1
[All PT0-002 Questions]

In an unprotected network file repository, a penetration tester discovers a text file containing usernames and passwords in cleartext and a spreadsheet containing data for 50 employees, including full names, roles, and serial numbers. The tester realizes some of the passwords in the text file follow the format: . Which of the following would be the best action for the tester to take NEXT with this information?

  • A. Create a custom password dictionary as preparation for password spray testing.
  • B. Recommend using a password manager/vault instead of text files to store passwords securely.
  • C. Recommend configuring password complexity rules in all the systems and applications.
  • D. Create a TPM-backed sealed storage location within which the unprotected file repository can be reported.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kloug
Highly Voted 1 year, 10 months ago
bbbbbbbb
upvoted 5 times
[Removed]
1 year, 10 months ago
Why B ?
upvoted 2 times
...
...
halo9000
Most Recent 1 day, 15 hours ago
Selected Answer: B
B - issue was addressed
upvoted 1 times
...
pinderanttal
1 week, 6 days ago
Selected Answer: A
https://www.examtopics.com/discussions/comptia/view/77771-exam-pt1-002-topic-1-question-85-discussion/ The same question is differently answered by exam topic. which one do you go to?
upvoted 1 times
...
koala_lay
1 month, 4 weeks ago
Selected Answer: A
Tester do testing first
upvoted 2 times
...
a87d6a4
3 months, 2 weeks ago
Selected Answer: A
Since the penetration tester has already found passwords in a clear pattern, the next logical step in the engagement would be to leverage that information by creating a custom password dictionary. This would be used for password spray testing, which is a common step in testing weak or predictable password usage across systems. Why the other options are not the best next step: B. Recommend using a password manager/vault instead of text files to store passwords securely: While this is a valid recommendation, it's a remediation step, not an action the tester should immediately take next. The test should proceed with assessing how vulnerable the systems are.
upvoted 3 times
...
Sebatian20
8 months, 1 week ago
Selected Answer: A
The testing ain't finished till the fat lady sings. One would think that the next thing to do would be to report your finding right away as it's an unprotected area but as that isn't one of the answer; never look a gift horse in the mouth.
upvoted 1 times
...
Big_Dre
10 months, 3 weeks ago
Selected Answer: B
get your priorities right. sensitive data has already been discovered to be exposed. No need to exploit it further recommend protection
upvoted 1 times
...
WANDOOCHOCO
11 months, 2 weeks ago
Selected Answer: A
AAAAAAAAAAA
upvoted 1 times
...
Meep123
1 year ago
Selected Answer: A
Exploitation first, remediation after.
upvoted 2 times
...
danscbe
1 year ago
Selected Answer: B
The key words for what CompTIA is looking for here is in the beginning of the question: "in an unprotected repository". That should give a clue as to what answer addresses this.
upvoted 2 times
...
[Removed]
1 year, 1 month ago
Selected Answer: A
Answer is A. Look back at question #49
upvoted 1 times
...
solutionz
1 year, 5 months ago
Selected Answer: B
The immediate concern here is that the penetration tester has found sensitive information, including usernames and passwords, stored in cleartext in an unprotected location. Before moving on to any kind of additional testing or exploitation, the priority should be to address this significant security risk. Among the options provided, the best next step would be: B. Recommend using a password manager/vault instead of text files to store passwords securely. This recommendation directly addresses the vulnerability that has been discovered and offers a practical solution to enhance security. It focuses on ensuring that the sensitive data is properly protected, rather than immediately moving forward with further penetration testing activities.
upvoted 4 times
...
lifehacker0777
1 year, 9 months ago
Selected Answer: A
__A__ https://www.examtopics.com/discussions/comptia/view/77771-exam-pt1-002-topic-1-question-85-discussion/
upvoted 1 times
...
Rob69420
1 year, 9 months ago
This is the SAME QUESTION as #49 and we have a different answer....
upvoted 3 times
...
cy_analyst
1 year, 9 months ago
Selected Answer: B
It's important to address critical security risks as soon as they are discovered. In this case, the discovery of a cleartext usernames and passwords file is a significant security risk that should be addressed as soon as possible to prevent any potential data breaches. While creating a custom password dictionary for password spray testing could also be a valid action for a penetration tester, it should not be the primary focus in this situation. The primary focus should be to address the security risk and make recommendations to the organization to improve its password practices.
upvoted 4 times
cy_analyst
1 year, 9 months ago
If the penetration tester waits until the end of the engagement to recommend a solution to the issue of passwords in clear text, there is a higher risk that the passwords could be discovered and exploited by malicious actors before the issue is addressed.
upvoted 3 times
...
...
[Removed]
1 year, 10 months ago
B is ithink the correct answer
upvoted 4 times
...
shakevia463
1 year, 11 months ago
Selected Answer: A
I say continue penetration testing by performing a and password spraying then document and suggest b and c
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago