hardMultiple Choice
FC0-U71 Practice Question: Refer to the exhibit
Exhibit
Refer to the exhibit. Application Configuration: <appSettings> <add key="DatabaseConnection" value="Server=prod01;Database=SalesDB;User Id=sa;Password=Passw0rd;" /> <add key="LogLevel" value="Debug" /> </appSettings>
Refer to the exhibit. A security auditor reviews this application configuration. What is the most significant security concern?
⚠ Common exam trap
The trap here is that candidates may focus on the 'Debug' log level (Option B) as a security risk due to verbosity, but the plaintext password (Option C) represents a direct, high-impact credential exposure that is far more critical.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The database password is stored in plaintext.
Storing a database password in plaintext within an application configuration file is a critical security vulnerability. If an attacker gains access to the file, they can immediately read the credentials and connect to the database, potentially compromising all stored data. This violates fundamental security principles such as least privilege and defense in depth, and it is explicitly warned against in secure coding guidelines like OWASP's Top 10 (A07:2021 – Identification and Authentication Failures).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The server name is hardcoded.
Why it's wrong here
A hardcoded server name is a maintainability and portability weakness, not an exploitable vulnerability; it exposes no credential or data. It is tempting because hardcoding looks like poor hygiene, and it would be the correct finding where the name embeds an internal hostname that aids reconnaissance.
- ✗
The log level is set to Debug.
Why it's wrong here
Debug logging records verbose internals, but it only becomes the top concern when it writes credentials, tokens or personal data to readable logs. It is tempting because debug output looks risky, and it would be correct where the exhibit shows secrets being logged in plaintext.
- ✓
The database password is stored in plaintext.
Why this is correct
Storing the database password as plaintext in a configuration file exposes credentials to anyone who reads that file, enabling direct database compromise. Hashing or using a secrets manager would remove this exposure, making plaintext storage the most significant concern.
- ✗
The database name is SalesDB.
Why it's wrong here
A database name such as SalesDB is ordinary configuration metadata and discloses nothing sensitive on its own. It is tempting because descriptive names hint at data content, and it would be the correct concern where the name itself leaks regulated data categories or credentials to unauthenticated users.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.