GPEN Reconnaissance Practice Question
During the reconnaissance phase of a penetration test, you are examining a target's public-facing web application. You notice that the application returns detailed error messages that include full file paths and database query snippets. Which of the following best describes the primary risk associated with this finding?
⚠ Common exam trap
The trap here is assuming that verbose errors directly cause a specific exploit like XSS or authentication bypass, when the real issue is the information leak that enables those attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It provides attackers with information that can be used to craft more targeted attacks
Detailed error messages are an information disclosure vulnerability. They reveal internal paths, database queries, and technology details that attackers can use to map the application and plan further attacks. This information is valuable for reconnaissance and can significantly reduce the effort required to exploit other vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It causes the application to crash, leading to a denial of service
Why it's wrong here
While some error messages might indicate unhandled exceptions, they do not inherently cause a denial of service. The application may continue to function normally. The primary risk is the exposure of sensitive information, not service disruption. Denial of service would require a separate attack vector, such as resource exhaustion or malformed input that triggers a crash.
- ✗
It allows attackers to perform cross-site scripting (XSS) attacks
Why it's wrong here
Detailed error messages do not directly enable XSS. XSS occurs when user input is reflected without proper sanitization, allowing script execution in the victim's browser. While error messages could potentially contain reflected input, they are not the primary risk here. The exposure of internal paths and queries is more relevant to information disclosure, which can aid further attacks like SQL injection or path traversal.
- ✗
It enables attackers to bypass authentication mechanisms
Why it's wrong here
Error messages do not directly bypass authentication. Authentication bypass typically involves flaws like SQL injection in login forms, weak credentials, or session fixation. While error messages might reveal database structure that could aid SQL injection, they themselves do not bypass authentication. The risk is information leakage, not direct authentication compromise.
- ✓
It provides attackers with information that can be used to craft more targeted attacks
Why this is correct
Detailed error messages reveal internal file paths, database structure, and query logic, which are valuable for an attacker. This information can be used to identify the technology stack, locate vulnerabilities, and craft precise exploits. For example, knowing the database type and version can help tailor SQL injection payloads. This is a classic information disclosure vulnerability that aids reconnaissance.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.