easyMultiple Choice
PT0-002 Practice Question: A penetration tester is conducting information…
A penetration tester is conducting information gathering on a target organization. The tester discovers a public code repository that contains configuration files with embedded credentials. Which of the following is the BEST next step?
⚠ Common exam trap
Many candidates confuse passive reconnaissance with active exploitation, thinking that documenting and moving on is sufficient, when in fact exposed credentials demand immediate action to prevent real-world compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Notify the organization's security team of the exposed credentials.
The tester has discovered exposed credentials in a public code repository, which is a critical security finding that requires immediate disclosure to the organization's security team. Ethical penetration testing mandates that any discovered vulnerabilities, especially those involving credential exposure, be reported promptly to prevent unauthorized access and potential data breaches. Proceeding with further exploitation without authorization violates the rules of engagement and could cause legal or operational harm.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Notify the organization's security team of the exposed credentials.
Why this is correct
Exposed credentials are an active risk indicator, not merely a data point for the report. By notifying the organization's security team immediately, the pentester enables them to rotate affected accounts, investigate potential prior misuse, and harden authentication controls before a real attacker exploits them. This action aligns with responsible-disclosure obligations and the rules of engagement that prioritize minimizing harm to the client.
- ✗
Attempt to crack the passwords to gain further access.
Why it's wrong here
Attempting to crack the discovered passwords escalates the engagement from passive information gathering into active exploitation without explicit authorization. Offline or online cracking may exceed the statement of work, trigger account lockout policies, or generate alerts that contaminate the client's security monitoring. It also converts the tester from an observer into a potential cause of credential-based damage, violating the confidentiality principle that underpins professional pentesting.
- ✗
Document the findings and proceed with passive reconnaissance.
Why it's wrong here
While documenting the exposed credentials is necessary, merely recording them and continuing passive reconnaissance fails to address the time-sensitive threat the leak represents. Every hour the client remains unaware, the credentials can be exploited by an actual adversary, so the tester has a professional duty to escalate the finding immediately. Passive reconnaissance cannot mitigate the presenting risk, and the delay could invalidate the value of the entire assessment.
- ✗
Use the credentials to log into the target system immediately.
Why it's wrong here
Using the credentials to log into the target system without prior approval in the rules of engagement crosses the boundary between reconnaissance and hands-on-keyboard intrusion. Even if the accounts are valid, authenticating with them may alter data, trigger access alarms, or constitute unauthorized access under the client's authorization and applicable computer-crime laws. This action also compromises the integrity of the test because any actions taken cannot be attributed to approved scope and may cause unintended damage to production systems.
Go deeper
Related to this question
Learn chapter
Penetration Testing Tools
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
Key term
Active reconnaissance
Active reconnaissance is the process of directly interacting with a target system or network to gather information, often through scanning and probing.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.