GPEN Advanced Password Attacks Practice Question
What is the primary risk associated with storing credentials in plain text within scripts or configuration files?
⚠ Common exam trap
Candidates often overthink the risk as 'data leakage' or 'compliance violation.' While true, the technical impact in a penetration test is the ability to bypass authentication entirely without needing to perform cracking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It allows an attacker to bypass authentication without cracking.
Storing cleartext credentials is a critical security failure because it provides an immediate, usable password to any attacker who gains read access to the file system. This often leads to lateral movement and privilege escalation because these scripts are frequently used by administrators to automate tasks across multiple servers. Identifying these files is a major component of any internal penetration test's post-exploitation phase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It increases the complexity of the password hashes.
Why it's wrong here
Storing passwords in plain text has no relationship with the complexity or quality of hashes generated by the system. It simply means the password is not hashed at all, which is a much larger security issue than the quality of the password's entropy or the hashing algorithm used.
- ✗
It prevents the use of multi-factor authentication.
Why it's wrong here
While storing a cleartext password is bad, it does not inherently prevent the use of MFA. However, many automated scripts that use stored credentials are often not configured for MFA, which is why they are targeted by attackers. The risk is the password exposure, not the lack of MFA compatibility.
- ✓
It allows an attacker to bypass authentication without cracking.
Why this is correct
If a script contains a cleartext password, an attacker who reads the file can immediately authenticate as the user or service account without the need for any complex cracking or relaying. This bypasses all authentication controls, providing direct access to whatever resources that account has been granted.
- ✗
It triggers an alert in the Windows Event Logs.
Why it's wrong here
Storing a password in a file does not generate an event log entry. Windows does not proactively audit file contents for cleartext credentials. Therefore, the risk is not that it is noisy or detectable, but rather that it is completely silent, allowing the credential theft to go entirely unnoticed.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.