nerdexam
CompTIA

PT0-002 · Question #363

During an engagement with a financial institution, a penetration tester found hard-coded credentials in a publicly accessible code repository. Those credentials allowed the penetration tester to acces

Sign in or unlock PT0-002 to reveal the answer and full explanation for question #363. The question stem and answer options stay visible for context.

Reporting and Communication

Question

During an engagement with a financial institution, a penetration tester found hard-coded credentials in a publicly accessible code repository. Those credentials allowed the penetration tester to access PII from many of the institution's customers and services that are hosted by a cloud provider. Which of the following actions should the penetration tester do next?

Options

  • AProceed with the engagement and add the evidence in the final report
  • BKeep the found credentials and use them during the engagement
  • CDisclose the findings through a bug bounty platform
  • DReport the findings to the customer's technical contact immediately

Unlock PT0-002 to see the answer

You've previewed enough free PT0-002 questions. Unlock PT0-002 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Incident Handling#Ethical Hacking#Vulnerability Disclosure#Customer Communication
Full PT0-002 Practice