PEN-200 Web Application Attacks Practice Question
Exhibit
Refer to the exhibit: [Config File: .htaccess] Options +Indexes
What is the most likely security risk associated with the configuration shown in the exhibit?
⚠ Common exam trap
Candidates sometimes confuse directory listing with Remote Code Execution or SQL injection, missing that exposed indexes primarily facilitate direct information disclosure of sensitive files.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attackers can browse the directory and discover sensitive files.
The 'Indexes' option enables directory listing, allowing attackers to browse the web server's file system if no index file is present. This is a significant information disclosure vulnerability because it exposes sensitive configuration files, backups, and source code that were never intended for public view. Disabling directory browsing is a fundamental hardening step for any web server to prevent accidental leakage of proprietary or sensitive infrastructure information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The server will allow remote code execution through the index file.
Why it's wrong here
Enabling indexes does not execute code; it merely lists files. While the list itself can expose sensitive files that an attacker might later use for RCE, the 'Indexes' configuration itself does not directly execute scripts, making this an incorrect characterization of the risk.
- ✓
Attackers can browse the directory and discover sensitive files.
Why this is correct
Enabling directory indexes allows the server to generate a listing of all files in a directory. This often reveals sensitive files like config.php, database dumps, or backup files that the administrator forgot to remove, giving the attacker a roadmap for further exploitation of the application.
- ✗
The configuration will prevent users from accessing any files.
Why it's wrong here
This configuration does the exact opposite; it provides additional access by allowing users to view the contents of directories. It is not an access control restriction, but rather a permissive setting that broadens the scope of what is visible to users on the server.
- ✗
The server will stop processing PHP files entirely.
Why it's wrong here
The 'Indexes' option is completely unrelated to the server's ability to interpret PHP or other server-side scripting languages. It only affects how the web server handles directory requests, so changing this setting will have no impact on the execution of PHP scripts.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.