Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester is conducting information…

A penetration tester is conducting information gathering on a target organization. The tester discovers a public code repository that contains configuration files with embedded credentials. Which of the following is the BEST next step?

⚠ Common exam trap

Many candidates confuse passive reconnaissance with active exploitation, thinking that documenting and moving on is sufficient, when in fact exposed credentials demand immediate action to prevent real-world compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Notify the organization's security team of the exposed credentials.

The tester has discovered exposed credentials in a public code repository, which is a critical security finding that requires immediate disclosure to the organization's security team. Ethical penetration testing mandates that any discovered vulnerabilities, especially those involving credential exposure, be reported promptly to prevent unauthorized access and potential data breaches. Proceeding with further exploitation without authorization violates the rules of engagement and could cause legal or operational harm.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Notify the organization's security team of the exposed credentials.

    Why this is correct

    Exposed credentials are an active risk indicator, not merely a data point for the report. By notifying the organization's security team immediately, the pentester enables them to rotate affected accounts, investigate potential prior misuse, and harden authentication controls before a real attacker exploits them. This action aligns with responsible-disclosure obligations and the rules of engagement that prioritize minimizing harm to the client.

  • ✗

    Attempt to crack the passwords to gain further access.

    Why it's wrong here

    Attempting to crack the discovered passwords escalates the engagement from passive information gathering into active exploitation without explicit authorization. Offline or online cracking may exceed the statement of work, trigger account lockout policies, or generate alerts that contaminate the client's security monitoring. It also converts the tester from an observer into a potential cause of credential-based damage, violating the confidentiality principle that underpins professional pentesting.

  • ✗

    Document the findings and proceed with passive reconnaissance.

    Why it's wrong here

    While documenting the exposed credentials is necessary, merely recording them and continuing passive reconnaissance fails to address the time-sensitive threat the leak represents. Every hour the client remains unaware, the credentials can be exploited by an actual adversary, so the tester has a professional duty to escalate the finding immediately. Passive reconnaissance cannot mitigate the presenting risk, and the delay could invalidate the value of the entire assessment.

  • ✗

    Use the credentials to log into the target system immediately.

    Why it's wrong here

    Using the credentials to log into the target system without prior approval in the rules of engagement crosses the boundary between reconnaissance and hands-on-keyboard intrusion. Even if the accounts are valid, authenticating with them may alter data, trigger access alarms, or constitute unauthorized access under the client's authorization and applicable computer-crime laws. This action also compromises the integrity of the test because any actions taken cannot be attributed to approved scope and may cause unintended damage to production systems.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.