nerdexam
CompTIA

PT0-003 · Question #143

During a penetration test of a web application, the tester gains full access to the application's source code. The application repository includes thousands of code files. Given that the assessment ti

Sign in or unlock PT0-003 to reveal the answer and full explanation for question #143. The question stem and answer options stay visible for context.

Submitted by thandi_sa· Mar 6, 2026Vulnerability discovery and analysis

Question

During a penetration test of a web application, the tester gains full access to the application's source code. The application repository includes thousands of code files. Given that the assessment timeline is very short, which of the following approaches would allow the tester to identify hard-coded credentials most effectively?

Options

  • ARun TruffleHog against a local clone of the application
  • BScan the live web application using Nikto
  • CPerform a manual code review of the Git repository
  • DUse SCA software to scan the application source code

Unlock PT0-003 to see the answer

You've previewed enough free PT0-003 questions. Unlock PT0-003 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Source code analysis#Hard-coded credentials#TruffleHog#Vulnerability discovery
Full PT0-003 Practice