A candidate must locate a relevant public exploit, read and understand it, set correct options such as LHOST and target port, and execute it safely. The single most important thing is verifying the exploit matches the target version and that your listener and callback path actually work.
Start practicing
Public Exploits — choose a session length
Free · No account required
Domain overview
This domain covers finding, evaluating, adapting, and safely executing public exploit code against target services. PEN-200 tests it through hands-on scenarios: locating a PoC for a known CVE, understanding what the script actually does, adjusting payload options like LHOST, and troubleshooting failures such as connection errors or missing callbacks.
Exam objectives
Reading exploit source to identify required arguments, hardcoded paths, and payload type before execution
Setting correct LHOST/LPORT values and matching reverse-shell payloads to the target OS and architecture
Diagnosing failures such as connection refused, closed ports, and blocked outbound callbacks from the target
Adapting PoCs for Windows features like Print Spooler and attacker-hosted SMB shares serving malicious DLLs
Running a public exploit without reading its code or verifying the target version, causing crashes or unintended damage
Leaving default LHOST/LPORT or using a payload mismatched to the target architecture, so no shell returns
Assuming a reported success means code execution, when the callback was blocked by a firewall or wrong interface
Click any question to see the full explanation and answer options, or start a focused practice session above.
You have identified a vulnerable service using an outdated version of a CMS. You successfully locate a public exploit script on GitHub. What is the most critical first step before running this script against your target?
2Which repository is generally considered the most reliable starting point for finding verified, community-contributed public exploits during an OSCP assessment?
3When modifying a public exploit to fit your specific target, which TWO of the following actions are considered best practices? (Choose TWO)
4Refer to the exhibit. You identify an Apache 2.4.49 vulnerability and locate the exploit. After reviewing the exploit code, you realize it requires a specific input format to trigger the path traversal. What is the most effective way to verify the vulnerability without crashing the server?
5Why might a public exploit for a specific service fail to execute even when the service version matches the vulnerability description exactly?
6When using Searchsploit, what is the purpose of the '-m' flag?
7You have found a Python exploit that uses the 'requests' library but your target machine only has standard Python installed. What is your best course of action?
8Refer to the exhibit. You are running a public exploit, but it fails with a 'Connection refused' error. What should you investigate first?
9Why is it important to use a local listener that matches the protocol expected by your exploit's payload?
10When analyzing a public exploit, which TWO elements should you specifically look for to understand its networking behavior? (Choose TWO)
11When an exploit script uses hardcoded memory addresses, why is it likely to fail on a modern target system?
12What is the primary danger of using a public exploit without first auditing the source code?
13You have identified an outdated version of a web application running on a target. You found a public exploit script for this version on Exploit-DB. Which step is most critical before executing the exploit script against the target?
14Which resource is most reliable for verifying that a public exploit is legitimate and does not contain hidden backdoors?
15You are reviewing a public exploit for a Linux-based web application. The exploit is a Python script that uses a hardcoded offset to overwrite a return address, and it includes a comment stating it was tested on a specific kernel version. Your target runs a different kernel but the same application version. After running the exploit, the service crashes but no shell is obtained. Which action is the MOST appropriate next step?
16You are reviewing a public exploit for a Linux-based web application. The exploit script contains a function that constructs a payload using a format string vulnerability. Which of the following best describes the primary risk of using this exploit without modification on a target with a different libc version?
17You download a public exploit for a known vulnerability from an untrusted source. Before running it against a client's production system, what is the most important action to take?
18You are assessing a Windows host and discover the Print Spooler service is running. You locate a public PoC for CVE-2021-1675 that requires an attacker-controlled SMB share hosting a malicious DLL. You want to execute the exploit from your Kali machine against the target. Which action must you take FIRST before running the PoC?
19During a PEN-200 lab engagement you locate a public exploit for a web application running on the target. The exploit's banner string is 'Mozilla/5.0' and the script appends the payload to a URL parameter. Before running it against the target, which action best reduces the risk of unintended side effects on the production web service?
20During an internal assessment, you find a public exploit for a Jenkins script console vulnerability. The exploit sends a Groovy script to /script via a POST request. When you run it, the server returns HTTP 403. The Jenkins version matches the vulnerable range, and the endpoint is reachable. Which is the MOST likely reason the exploit fails?
21A public exploit for a Linux service includes a compiled payload that connects back to a hardcoded IP address. You need to adapt it for your PEN-200 engagement. Which TWO actions are most appropriate? (Choose two.)
22You download a public exploit from Exploit-DB for a known vulnerability in a web application. Before running it against a client's production server, which action is the MOST appropriate next step?
23You download a public exploit archive from an unknown source. Before using it in the PEN-200 lab, which step best protects your own attacking machine from a trojanized exploit?
24You are adapting a public Python exploit for a Windows target. The exploit was written for a different architecture and uses a hardcoded payload. Which TWO actions are MOST appropriate to make the exploit work reliably? (Choose two.)
25A public exploit for a Windows service is written in Python and uses the 'impacket' library. On your Kali attacker machine, running it fails with an ImportError for impacket. What is the most appropriate next step?
26You are adapting a public exploit whose payload is a reverse shell. The exploit runs and the service reports success, but your netcat listener never receives a connection. Which cause is most likely?
27During a PEN-200 lab exercise, you find a public exploit for a Windows service. The exploit source contains a hardcoded return address of 0x41414141 and a comment that it was tested against a different Windows build with ASLR disabled. What should you do before running it against your target?
A candidate must locate a relevant public exploit, read and understand it, set correct options such as LHOST and target port, and execute it safely. The single most important thing is verifying the exploit matches the target version and that your listener and callback path actually work.
The Courseiva PEN-200 question bank contains 27 questions in the Public Exploits domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Public Exploits domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included