Courseiva

GPEN Password Attacks and Formats Practice Question

What is the main risk associated with storing cleartext credentials in environment variables or configuration files?

⚠ Common exam trap

Many test-takers look for complex cryptographic flaws and overlook simple operational oversights like local file permission misconfigurations exposing cleartext credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

They can be read by any user or process with sufficient file permissions.

Cleartext credentials are easily accessible to anyone with local read access. In a penetration test, finding these files is a 'low-hanging fruit' that often leads to privilege escalation or lateral movement. Many applications inadvertently store sensitive data in logs, config files, or scripts, creating a security debt that attackers exploit to gain unauthorized access without needing to crack passwords through time-consuming cryptographic analysis of captured hashes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    They are susceptible to rainbow table attacks.

    Why it's wrong here

    Rainbow table attacks target hashed values. Cleartext credentials do not require any cracking or reverse-engineering, as they are already readable. Therefore, the concept of a rainbow table is entirely irrelevant because the secret is already exposed in its original, human-readable format, requiring zero computational effort to recover.

  • ✓

    They can be read by any user or process with sufficient file permissions.

    Why this is correct

    If a file containing cleartext credentials has overly permissive access controls, any local user or compromised process can read the file. This allows attackers to harvest high-value credentials without ever needing to perform complex password attacks, making it a critical finding during any security assessment or audit.

  • ✗

    They prevent the use of multi-factor authentication.

    Why it's wrong here

    Cleartext storage of passwords has no direct relationship with the implementation of MFA. While the password itself is compromised, MFA might still be required for access depending on the target application. The danger lies in the direct exposure of the secret, not in the interference with secondary authentication.

  • ✗

    They automatically trigger account lockouts after one reading.

    Why it's wrong here

    Reading a file containing a password does not constitute an authentication attempt against an identity provider. Therefore, no account lockout mechanisms are triggered. The risk is simply the unauthorized disclosure of the secret, which an attacker can then use at their leisure to authenticate as the victim.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.