GPEN Password Attacks and Formats Practice Question
What is the main risk associated with storing cleartext credentials in environment variables or configuration files?
⚠ Common exam trap
Many test-takers look for complex cryptographic flaws and overlook simple operational oversights like local file permission misconfigurations exposing cleartext credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They can be read by any user or process with sufficient file permissions.
Cleartext credentials are easily accessible to anyone with local read access. In a penetration test, finding these files is a 'low-hanging fruit' that often leads to privilege escalation or lateral movement. Many applications inadvertently store sensitive data in logs, config files, or scripts, creating a security debt that attackers exploit to gain unauthorized access without needing to crack passwords through time-consuming cryptographic analysis of captured hashes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
They are susceptible to rainbow table attacks.
Why it's wrong here
Rainbow table attacks target hashed values. Cleartext credentials do not require any cracking or reverse-engineering, as they are already readable. Therefore, the concept of a rainbow table is entirely irrelevant because the secret is already exposed in its original, human-readable format, requiring zero computational effort to recover.
- ✓
They can be read by any user or process with sufficient file permissions.
Why this is correct
If a file containing cleartext credentials has overly permissive access controls, any local user or compromised process can read the file. This allows attackers to harvest high-value credentials without ever needing to perform complex password attacks, making it a critical finding during any security assessment or audit.
- ✗
They prevent the use of multi-factor authentication.
Why it's wrong here
Cleartext storage of passwords has no direct relationship with the implementation of MFA. While the password itself is compromised, MFA might still be required for access depending on the target application. The danger lies in the direct exposure of the secret, not in the interference with secondary authentication.
- ✗
They automatically trigger account lockouts after one reading.
Why it's wrong here
Reading a file containing a password does not constitute an authentication attempt against an identity provider. Therefore, no account lockout mechanisms are triggered. The risk is simply the unauthorized disclosure of the secret, which an attacker can then use at their leisure to authenticate as the victim.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.