A library's LDAP configuration allows anonymous or overly broad read of sensitive directory attributes. What should the tester flag?
Select an answer to reveal the explanation.
Short Explanation
LDAP that talks too freely is like a receptionist who hands out employee files to anyone who asks. That disclosure greases recon and can leak sensitive attributes. Tighten who can read what.
Full Explanation
Overly permissive LDAP anonymous binds or broad read rights increase reconnaissance value and can expose sensitive attributes to unauthorized or low-privilege principals. This is directory information disclosure, not a required default for modern AD nor a resilience feature. Restricting LDAP visibility is part of identity hardening and reduces attack-path mapping ease for adversaries.