In an unprotected network file repository, a penetration tester discovers a text file containing usernames and passwords in cleartext and a spreadsheet containing data for 50 employees, including full names, roles, and serial numbers. The tester realizes some of the passwords in the text file follow the format: <name-serial_number> . Which of the following would be the best action for the tester to take NEXT with this information?
A) Create a custom password dictionary as preparation for password spray testing.
B) Recommend using a password manage/vault instead of text files to store passwords securely.
C) Recommend configuring password complexity rules in all the systems and applications.
D) Document the unprotected file repository as a finding in the penetration-testing report.
Correct Answer:
Verified
Q38: A software development team is concerned that
Q39: A penetration tester has identified several newly
Q40: A penetration tester needs to perform a
Q41: A penetration tester was able to gain
Q42: Which of the following is the MOST
Q44: A penetration tester has been hired to
Q45: User credentials were captured from a database
Q46: An Nmap network scan has found five
Q47: A penetration tester discovers that a web
Q48: A penetration tester discovered a vulnerability that
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents