ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 418 - PT0-002 discussion

Report
Export

A penetration tester was able to gain access to a plaintext file on a user workstation. Upon opening the file, the tester notices some strings of randomly generated text. The tester is able to use these strings to move laterally throughout the network by accessing the fileshare on a web application. Which of the following should the organization do to remediate the issue?

A.
Sanitize user input.
Answers
A.
Sanitize user input.
B.
Implement password management solution.
Answers
B.
Implement password management solution.
C.
Rotate keys.
Answers
C.
Rotate keys.
D.
Utilize certificate management.
Answers
D.
Utilize certificate management.
Suggested answer: B

Explanation:

The presence of plaintext strings that can be used to move laterally across the network suggests that passwords or sensitive tokens are stored insecurely. Implementing a password management solution would help mitigate this issue by ensuring that passwords are stored securely and are not exposed in plaintext. Password managers typically use strong encryption to protect stored credentials and provide secure access to them.

Sanitizing user input, rotating keys, and utilizing certificate management address different aspects of security but do not directly resolve the issue of insecure password storage.

Importance of password management: NIST Password Guidelines

Examples of security breaches due to poor password management practices: Forge.

asked 02/10/2024
Wilco Gent
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first