Courseiva
Password Attacks →easyMultiple Choice

PEN-200 Password Attacks Practice Question

You are auditing a web application and notice it uses base64 encoding to store user credentials in a cookie. What is the most accurate assessment of this security practice?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The implementation is insecure because base64 is an encoding, not a cryptographic protection.

Base64 is an encoding scheme, not an encryption or hashing algorithm. It is completely reversible and provides zero confidentiality for sensitive data. An attacker can easily decode these values to reveal plaintext credentials. This is a common finding in penetration tests that highlights a lack of understanding of the difference between obfuscation and actual security controls, requiring immediate remediation to protect session integrity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The credentials are secure because base64 is difficult to reverse without the secret key.

    Why it's wrong here

    Base64 is a public, reversible encoding scheme that requires no secret key for decoding. Anyone with access to the encoded string can transform it back into its original format effortlessly. Claiming it is secure is a dangerous misconception that leaves user credentials exposed to anyone who can intercept the traffic.

  • ✗

    The credentials are protected from casual inspection but vulnerable to automated tools.

    Why it's wrong here

    Base64 provides no protection against either casual inspection or automated tools. Because it is a standardized format, any browser, proxy, or simple script can decode it instantly. It offers no security benefits and should never be used as a mechanism for protecting sensitive data like passwords or session identifiers.

  • ✓

    The implementation is insecure because base64 is an encoding, not a cryptographic protection.

    Why this is correct

    Base64 is designed to represent binary data in an ASCII string format. It offers no confidentiality or integrity. Using it to store credentials is a critical vulnerability because it exposes plaintext passwords to anyone who can view the cookie, allowing for trivial credential theft and subsequent unauthorized account access by an attacker.

  • ✗

    The implementation is acceptable if the connection is encrypted with TLS.

    Why it's wrong here

    While TLS protects data in transit, storing credentials in a cookie in base64 format is still insecure at rest on the client machine. If the client machine is compromised or if the browser history is accessed, the credentials remain exposed. Proper security requires hashing or robust session management tokens.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.