Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

You are enumerating an Apache web server and discover the '.git' directory is accessible. What is the most significant risk this poses for your reconnaissance?

⚠ Common exam trap

Candidates often assume the risk is just file disclosure or directory listing. The most significant risk is the full repository download, which provides the entire codebase and sensitive history.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The entire source code repository can be downloaded.

An exposed '.git' directory allows an attacker to download the entire project repository, including source code, configuration files, and commit history. This is a critical discovery because the source code may contain hardcoded credentials, API keys, or sensitive business logic that would otherwise be hidden. Analyzing this data often provides the most direct path to exploitation, as it reveals the application's internal workings and potential flaws that are not apparent from the outside.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It indicates the server is using an outdated version of Apache.

    Why it's wrong here

    The presence of a .git directory is a configuration error of the application deployment, not the web server software itself. It implies that the version control metadata was accidentally uploaded, which is a distinct issue from the underlying Apache server version and should be treated as such.

  • ✓

    The entire source code repository can be downloaded.

    Why this is correct

    Exposed .git directories allow an attacker to reconstruct the entire project repository, including code, database schema, and configuration files. This provides deep insight into the application's internal structure and security logic, exposing credentials or secrets that are frequently hardcoded by developers during the initial phases of coding.

  • ✗

    It means the server is vulnerable to SQL injection.

    Why it's wrong here

    While the source code might reveal SQL injection vulnerabilities, the presence of a .git directory itself does not imply that the application is vulnerable. It is a source of information that requires manual analysis; the vulnerability is a separate issue that must be discovered through careful code review.

  • ✗

    It suggests that the server is running on a Windows OS.

    Why it's wrong here

    Git is platform-independent and can be found on both Linux and Windows servers. The directory's existence is entirely independent of the operating system choice. Assuming the OS based on the presence of a Git directory is a logical fallacy and does not aid in your actual technical assessment.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.