Courseiva
Web Application Attacks →mediumMultiple Choice

PEN-200 Web Application Attacks Practice Question

Exhibit

Refer to the exhibit: 
[Config File: .htaccess]
Options +Indexes

What is the most likely security risk associated with the configuration shown in the exhibit?

⚠ Common exam trap

Candidates sometimes confuse directory listing with Remote Code Execution or SQL injection, missing that exposed indexes primarily facilitate direct information disclosure of sensitive files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attackers can browse the directory and discover sensitive files.

The 'Indexes' option enables directory listing, allowing attackers to browse the web server's file system if no index file is present. This is a significant information disclosure vulnerability because it exposes sensitive configuration files, backups, and source code that were never intended for public view. Disabling directory browsing is a fundamental hardening step for any web server to prevent accidental leakage of proprietary or sensitive infrastructure information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The server will allow remote code execution through the index file.

    Why it's wrong here

    Enabling indexes does not execute code; it merely lists files. While the list itself can expose sensitive files that an attacker might later use for RCE, the 'Indexes' configuration itself does not directly execute scripts, making this an incorrect characterization of the risk.

  • ✓

    Attackers can browse the directory and discover sensitive files.

    Why this is correct

    Enabling directory indexes allows the server to generate a listing of all files in a directory. This often reveals sensitive files like config.php, database dumps, or backup files that the administrator forgot to remove, giving the attacker a roadmap for further exploitation of the application.

  • ✗

    The configuration will prevent users from accessing any files.

    Why it's wrong here

    This configuration does the exact opposite; it provides additional access by allowing users to view the contents of directories. It is not an access control restriction, but rather a permissive setting that broadens the scope of what is visible to users on the server.

  • ✗

    The server will stop processing PHP files entirely.

    Why it's wrong here

    The 'Indexes' option is completely unrelated to the server's ability to interpret PHP or other server-side scripting languages. It only affects how the web server handles directory requests, so changing this setting will have no impact on the execution of PHP scripts.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.