Reinforce PEN-200 concepts with active-recall study cards covering all 11 blueprint domains. Each card shows the question on the front and the correct answer with a full explanation on the back.
Flashcards work through active recall — the process of retrieving information from memory rather than passively re-reading it. Research consistently shows that active recall produces stronger, longer-lasting memory than re-reading study guides. For PEN-200 preparation, this means flashcards are one of the highest-return study tools available.
Attempt recall first
Read the PEN-200 question on each card, pause, and attempt to formulate the answer in your own words before revealing. This retrieval attempt — even if wrong — dramatically strengthens memory compared to immediately reading the answer.
Review wrong cards again
When you get a card wrong, note it and add it back to your review pile. Spaced repetition — seeing difficult cards more frequently — is the mechanism that makes flashcard study far more efficient than linear reading.
Study by domain
Group your PEN-200 flashcard sessions by domain for the first 3–4 weeks. Master one domain before moving to the next. In the final week, shuffle all cards together to test cross-domain recall — which is what the real PEN-200 exam requires.
Short sessions beat marathon reviews
20–30 flashcard cards per session, done daily, produces better retention than a single 200-card marathon session. Five short daily sessions per week over 4 weeks gives you over 400 total card reviews — enough to reliably pass PEN-200.
Sample cards from the PEN-200 flashcard bank. Read the question, think of the answer, then read the explanation below.
During an authorized penetration test, you want to perform a client-side attack by delivering a malicious HTA file via a phishing email. Which technique is most effective to execute native commands silently when the user opens the file?
Using mshta.exe to process a VBScript payload embedded within the HTA container to spawn a reverse shell
HTA files execute via mshta.exe, allowing VBScript or JScript integration to run operating system commands directly without standard browser security sandboxes. This makes HTA files highly effective for initial access vectors during social engineering engagements when users trust and run local executables.
You are performing a network scan on a target network and notice that ICMP echo requests are blocked, but you need to determine if the target host is alive. Which technique should you utilize to identify active hosts without relying on standard ICMP ping?
Perform a TCP SYN scan on common ports such as 80, 443, and 22.
When ICMP is filtered by firewalls, TCP SYN scanning on common ports like 80 or 443 is an effective alternative for host discovery. This technique works because the target system responds to a SYN packet with a SYN/ACK if the port is open, or an RST if closed, confirming the host's presence. Mastering non-ICMP discovery is critical for bypass techniques in hardened network environments where security policies block traditional discovery methods.
You have obtained a low-privileged domain user account and are performing internal enumeration. You identify a computer object in the domain where the 'ms-MCS-AdmPwd' attribute is readable by your user account. Which attack path does this vulnerability facilitate?
Extracting the cleartext local administrator password
The ms-MCS-AdmPwd attribute stores the cleartext Local Administrator Password for a computer managed by LAPS. By reading this attribute, an attacker can extract the password for the local administrator account of the target machine. This is a critical discovery because it allows immediate lateral movement from a low-privileged domain context to local administrative privileges on that specific host, potentially leading to further credential harvesting or domain escalation.
You have identified a vulnerable service using an outdated version of a CMS. You successfully locate a public exploit script on GitHub. What is the most critical first step before running this script against your target?
Read the source code to understand its mechanism and potential impact.
Before executing any public exploit, you must analyze the source code to understand its functionality, dependencies, and potential impact. Public exploits are often poorly written or intentionally malicious, potentially causing service crashes or backdooring the attacker machine. Understanding the payload ensures you do not inadvertently trigger unwanted side effects or trigger defensive alarms that could disrupt your assessment during the penetration testing engagement.
Which of the following describes a successful Path Traversal attack in a web application?
Using dot-dot-slash sequences to read /etc/passwd on a Linux server.
Path Traversal allows attackers to access files outside the intended web root directory by manipulating input parameters that contain file paths. By using dot-dot-slash sequences, an attacker escapes the restricted directory. This is a critical vulnerability that can lead to the exposure of configuration files, sensitive system data, or source code, which is why validating input is a fundamental security requirement.
You have gained a low-privileged shell on a Linux system and discovered a binary with the SUID bit set. The binary executes a system call to 'cat' without specifying an absolute path. How can you leverage this to escalate privileges?
Prepend a directory containing a malicious 'cat' script to the PATH variable and run the binary.
By manipulating the PATH environment variable, you can point the system to a malicious 'cat' executable created in a writable directory. When the SUID binary runs, it executes your script with the permissions of the file owner rather than yours. This technique exploits the insecure execution of external commands, a common vulnerability in improperly coded SUID binaries that allows for arbitrary command execution under an elevated security context.
You are analyzing a binary and identify a function that uses strcpy() to copy user input into a fixed-size stack buffer. Which register must be controlled to redirect the instruction pointer to your shellcode?
The saved Return Address on the stack
To redirect the execution flow, you must overwrite the saved Return Address on the stack. When a function finishes, the CPU pops the value at the saved EIP/RIP location into the Instruction Pointer. By overflowing the buffer and reaching this specific memory location, you gain control over the program's subsequent execution path, which is the foundational concept for stack-based buffer overflow exploitation in the PEN-200 curriculum.
You have compromised a Linux jump host and need to access an internal web application on 192.168.1.50:80 that is firewalled from your local machine. You have SSH access to the jump host. Which command should you execute on your local machine to securely access the application via your browser?
ssh -L 8080:192.168.1.50:80 user@jump-host
Local port forwarding allows you to tunnel traffic from a local port to a destination reachable by the SSH server. By mapping a local port to the internal web server's address, you bypass network restrictions imposed by firewalls. This technique is fundamental for pivoting through compromised hosts, enabling tools like Burp Suite or browsers to interact with internal services as if they were running locally, which is vital for further web application vulnerability assessment.
An analyst is attempting to execute a custom C2 stager on a Windows 10 workstation with active Windows Defender. They decide to use a PowerShell one-liner that downloads a script from a remote server and executes it directly using the Invoke-Expression (IEX) cmdlet. Why is this method generally more effective than downloading an .exe file to the Desktop?
Memory-only execution avoids the file-on-disk signature scanning process.
In-memory execution avoids the creation of files on the physical disk, which is where most traditional antivirus solutions perform their primary signature-based scanning. By keeping the malicious payload within the volatile memory of the PowerShell process, the attacker minimizes the forensic footprint and reduces the likelihood of triggering alerts associated with suspicious file creation or modification events on the local file system.
You have successfully obtained a NTLM hash dump from a domain controller. You intend to perform a pass-the-hash attack to move laterally. What is the most critical requirement for this technique to succeed in a modern Windows environment?
The authentication protocol must permit NTLM or legacy authentication methods to facilitate the hash usage.
Pass-the-hash (PtH) relies on the fact that authentication protocols like NTLM require the hash itself rather than the cleartext password. Understanding this mechanism is vital because it allows attackers to impersonate users without needing to crack complex passwords. The technique effectively bypasses the need for plaintext credentials, making it a staple for lateral movement in internal penetration tests when local administrator or service account access is achieved.
You have gained a low-privileged shell on a Windows system and discovered a service running as 'LocalSystem' with an unquoted executable path containing spaces. Which action is the most direct way to escalate privileges?
Place a malicious binary at a location in the unquoted path that the user can write to.
Unquoted service paths are vulnerable because Windows attempts to resolve the path by interpreting spaces as delimiters. By placing a malicious executable at an intermediate folder in the path, the service manager executes your binary with SYSTEM privileges upon restart. Identifying and exploiting these paths is a foundational skill for post-exploitation, allowing attackers to elevate from standard user to the highest possible integrity level without needing complex kernel exploits.
The PEN-200 flashcard bank covers all 11 official blueprint domains published by OffSec. Cards are distributed proportionally, so domains with higher exam weight have more cards.
Domain Coverage
Client-Side Attacks
Enumeration and Reconnaissance
Active Directory Attacks
Public Exploits
Web Application Attacks
Linux Privilege Escalation
Buffer Overflow Fundamentals
Port Redirection and Tunneling
Antivirus Evasion
Password Attacks
Windows Privilege Escalation
Both flashcards and practice questions are evidence-based study tools. The difference is in what they train:
Flashcards — concept retention
Best for memorising definitions, acronyms, protocol behaviours, command syntax, and conceptual distinctions. Use flashcards to build the foundational vocabulary that PEN-200 questions assume you know.
Best in: weeks 1–3
Practice tests — application
Best for applying concepts to realistic scenarios, eliminating distractors, and building exam stamina.PEN-200 questions test scenario reasoning — not just recall — so practice tests are essential.
Best in: weeks 3–6
The most effective PEN-200 study plan combines both: use flashcards for the first 2–3 weeks to build conceptual foundations, then shift to practice tests and mock exams in the final 2–3 weeks to apply and benchmark that knowledge. Most candidates who pass on their first attempt use both tools.
Yes. Courseiva provides free PEN-200 flashcards across all official exam domains. Every card includes the correct answer and a full explanation of why it is right and why the distractors are wrong. The platform also includes topic-based practice, mock exams, and readiness tracking — no account required.
Courseiva has 285+ original PEN-200 flashcards across all 11 exam blueprint domains. New cards are added regularly as the question bank grows. All cards are checked against the official OffSec exam objectives, with editorial oversight from an experienced network and security engineer.
Courseiva flashcards are purpose-built for IT certification exams. Unlike generic flashcard platforms where content quality varies, every Courseiva card is mapped to the official PEN-200 exam blueprint, written by engineers who hold the certification, and includes a full explanation of the correct answer and why the distractors are wrong. This explanation quality is what separates genuine learning from rote memorisation.
Courseiva is a web platform — an internet connection is required. For offline study, we recommend creating free Courseiva account, using the platform in your browser, and using your device's offline capabilities if your browser supports offline web apps.
Save your results, see which domains need more work, and get spaced repetition recommendations — all free.
Sign Up FreeFree forever · Every certification included