Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: During a security assessment, a penetration…

During a security assessment, a penetration tester captures unencrypted credentials over the network. Which protocol is most likely being used?

⚠ Common exam trap

ISC2 often tests the distinction between protocols that use encryption (like HTTPS, SSH, SMTPS) and those that do not (like FTP, Telnet, HTTP), and the trap here is that candidates may confuse FTP with its secure variants (FTPS or SFTP) or assume all file transfer protocols are encrypted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FTP

FTP (File Transfer Protocol) transmits data, including credentials, in cleartext over the network. When a penetration tester captures unencrypted credentials, FTP is a likely candidate because it does not encrypt the authentication process, making it vulnerable to packet sniffing attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SMTPS

    Why it's wrong here

    SMTPS wraps SMTP in TLS, encrypting the authentication exchange, so credentials would not appear in cleartext. It is tempting because mail protocols are common credential-capture targets, but SMTPS is the secured variant; plain SMTP would be the correct choice.

  • ✗

    SSH

    Why it's wrong here

    SSH encrypts the entire session, including authentication, so captured credentials would be ciphertext. It is tempting because SSH is a remote-access protocol often seen in assessments, but it would be the answer if the tester captured encrypted traffic.

  • ✓

    FTP

    Why this is correct

    FTP transmits both authentication credentials and data in cleartext, with no encryption layer, so a sniffer on the path captures usernames and passwords directly. Alternatives such as FTPS, SFTP, or HTTPS wrap the session in TLS, which would have rendered the captured credentials unreadable.

  • ✗

    HTTPS

    Why it's wrong here

    HTTPS encrypts HTTP traffic with TLS, protecting credentials in transit, so a capture would show ciphertext. It is tempting because web logins are frequent targets, but HTTPS is the secured form; unencrypted HTTP would be the correct answer.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.