You must craft and host client-side payloads, deliver them to a victim, and catch the resulting shell. The single most important thing is matching the payload to the execution context and having the correct handler or web server already running before the target interacts.
Start practicing
Client-Side Attacks — choose a session length
Free · No account required
Domain overview
This domain covers attacking a victim's browser or client application rather than the server directly. On PEN-200 you must build malicious HTA, macro, or library payloads, host them with a web server, and gain code execution when a user opens them. Testing focuses on payload delivery, execution context, and post-exploitation of the client host.
Exam objectives
Delivering malicious HTA files that run native commands via mshta.exe on Windows targets
Building Microsoft Office macros that invoke PowerShell or cmd for initial execution
Using Metasploit browser exploits and malicious document handlers for client-side code execution
Identifying XSS input contexts such as HTML body, attributes, and script blocks that allow injection
Assuming a malicious file executes without user interaction; most client-side attacks require the victim to open or enable content
Forgetting to start the matching listener or web server before sending the payload, so no session returns
Testing XSS in only one context and missing attribute, JavaScript, or URL contexts that need different payload syntax
Click any question to see the full explanation and answer options, or start a focused practice session above.
During an authorized penetration test, you want to perform a client-side attack by delivering a malicious HTA file via a phishing email. Which technique is most effective to execute native commands silently when the user opens the file?
2You are analyzing a target web application that reflects user input directly into an HTML attribute without proper sanitization. Which vulnerability class should you primarily investigate for exploitation?
3During a web application assessment, you discover that the application allows users to upload profile pictures. The server saves these files with their original extensions in a publicly accessible directory. What is the most effective client-side risk associated with this misconfiguration?
4You are conducting a client-side attack using a weaponized Microsoft Office document containing a malicious VBA macro. Which user interaction and application setting combination is required for the macro to execute successfully by default?
5During an assessment, you identify a Cross-Site Scripting vulnerability that allows you to execute arbitrary JavaScript in the context of a victim user's browser session. What is the primary objective of leveraging this capability against an authenticated user?
6When evaluating a web application for Cross-Site Scripting vulnerabilities during a penetration test, which TWO input contexts should you examine because they frequently lead to executable script injection?
7You are performing a client-side phishing engagement and need to deliver a malicious payload using an ISO image file. Why is this delivery method often effective against modern Windows security warnings?
8Refer to the exhibit. ```http HTTP/1.1 200 OK Server: nginx Content-Type: text/html; charset=UTF-8 Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' <html> <body> <h1>Welcome</h1> <script>var token = '12345';</script> </body> </html> ``` Based on the HTTP response headers and body shown in the exhibit, what significant security risk is present regarding client-side attacks?
9When testing for DOM-based XSS, where should you focus your analysis to find the vulnerable code?
10Which property of a URL is most commonly used as a source for DOM-based XSS because it is not sent to the server?
11Which of the following describes the 'Open Redirect' vulnerability often used in phishing attacks?
12What is the primary objective of a 'Clickjacking' attack?
13During an authorized penetration test, you discover that a web application’s password reset page reflects the `email` parameter inside a JavaScript string literal with no output encoding. You want to execute arbitrary JavaScript in a victim’s browser when they click a crafted password-reset link. Which payload should you use?
14During an authorized internal penetration test, you discover that the corporate proxy does not perform SSL inspection and allows outbound HTTPS to any destination. You need to deliver a client-side payload over HTTPS while evading signature-based network detection. Which technique is most appropriate?
15You are testing a web application that sets a session cookie with the HttpOnly flag. You find a reflected XSS vulnerability on a page that does not require authentication. What is the primary impact of exploiting this XSS given the HttpOnly flag?
16During an authorized penetration test, you deliver a malicious script to a victim's browser by exploiting a reflected XSS vulnerability. The script executes in the context of the vulnerable application and silently sends a crafted HTTP request to the application's password-change endpoint. The victim is currently authenticated. Which client-side attack technique are you performing?
17You are performing a client-side attack against a target web application that uses a Content Security Policy (CSP) with the directive `script-src 'self'`. Which TWO techniques are most likely to bypass this CSP and execute JavaScript in a victim’s browser? (Choose two.)
18You are assessing a web application that uses a strict Content Security Policy (CSP) with nonce-based script-src. You discover a reflected XSS vulnerability where your input is inserted into an existing <script> block that already has a valid nonce. Which action would most likely allow your JavaScript to execute despite the CSP?
19You are assessing a web application that reflects user input into an HTML attribute value without quotes, such as `<input value=USER_INPUT>`. Which payload is most likely to execute JavaScript in the victim’s browser?
20During a penetration test, you want to exploit a client-side vulnerability by sending a link that will execute JavaScript in a victim’s browser when clicked. The target application uses a session cookie without the SameSite attribute. Which attack is most directly enabled by the missing SameSite attribute?
21You are performing a client-side attack against a web application that uses a JSON Web Token (JWT) stored in localStorage for authentication. You have identified a stored XSS vulnerability. Which two actions could you perform to escalate privileges or maintain access? (Choose two.)
22During a penetration test, you discover that a web application uses an outdated version of a JavaScript library that contains a known DOM-based XSS vulnerability. The vulnerability is triggered when a specific URL parameter is processed by the library. Which action would best allow you to demonstrate the impact of this vulnerability to the client?
23You are crafting a malicious HTML Application (.hta) to deliver to a Windows user during a phishing engagement. When the file is opened, you want it to execute a PowerShell download cradle that fetches a second-stage payload. Which VBScript construct inside the HTA most directly spawns the hidden PowerShell process?
24During a client-side assessment, you find that an application accepts a user-supplied URL parameter and later uses it to redirect the browser away from the site without validating the destination. Which vulnerability class does this behavior represent, and what is its most direct client-side impact?
25You are building a malicious Microsoft Word document for a phishing campaign. You need the embedded macro to execute automatically as soon as the document is opened, without requiring the victim to click an additional button or dismiss a prompt beyond the initial security warning. Which document element must the macro reside in to achieve automatic execution?
You must craft and host client-side payloads, deliver them to a victim, and catch the resulting shell. The single most important thing is matching the payload to the execution context and having the correct handler or web server already running before the target interacts.
The Courseiva PEN-200 question bank contains 25 questions in the Client-Side Attacks domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Client-Side Attacks domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included