Courseiva
Public Exploits →hardMultiple Select

PEN-200 Public Exploits Practice Question

A public exploit for a Linux service includes a compiled payload that connects back to a hardcoded IP address. You need to adapt it for your PEN-200 engagement. Which TWO actions are most appropriate? (Choose two.)

⚠ Common exam trap

The trap here is treating the hardcoded IP as a network-routing problem to be solved with forwarding or firewall changes, when the address is compiled into the payload itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Edit the exploit source to replace the hardcoded IP with your attacker IP, then recompile the payload if the exploit includes source.

The hardcoded callback address must be replaced with the tester's reachable address, and the payload must match the target architecture. Regenerating with msfvenom or editing and recompiling the source both accomplish this while preserving the exploit's vulnerability trigger. Router forwarding and firewall changes do not alter the embedded address, and a bind shell changes the exploitation model unnecessarily.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the target firewall with an initial command so the hardcoded callback address becomes reachable.

    Why it's wrong here

    Disabling the firewall does not change the destination IP embedded in the payload, so the callback still travels to the wrong host. It also causes unnecessary configuration changes on the target, which violates the principle of minimal impact and could disrupt other services or alert defenders during the engagement.

  • ✓

    Edit the exploit source to replace the hardcoded IP with your attacker IP, then recompile the payload if the exploit includes source.

    Why this is correct

    When source is available, changing the callback address and recompiling produces a payload that is byte-for-byte appropriate for the target and avoids introducing a foreign binary. This is the most transparent adaptation because the tester can review every change, confirm the architecture matches, and verify the callback address before delivery to the target service.

  • ✗

    Replace the payload with a bind shell on a common port so no callback address is needed.

    Why it's wrong here

    Switching to a bind shell changes the exploitation model and often fails because the target's firewall blocks inbound connections to the bind port. It also replaces a working reverse-shell mechanism with a different one that may not fit the exploit's delivery constraints, introducing new failure points instead of correcting the hardcoded address.

  • ✓

    Use msfvenom to generate a new payload that matches the target architecture and set the LHOST to your tun0 address, then substitute it into the exploit.

    Why this is correct

    Regenerating the payload with msfvenom produces a payload compiled for the target architecture with the correct callback address embedded, which directly solves the hardcoded-IP limitation. Substituting it into the exploit preserves the vulnerability trigger while ensuring the callback returns to the tester's VPN interface, making the adapted exploit functional in the lab environment.

  • ✗

    Run the exploit as-is and rely on port forwarding on your router to redirect the callback to your machine.

    Why it's wrong here

    Port forwarding only redirects traffic that arrives at a public address the target can reach; in a lab VPN the target routes to the tun0 subnet, not the tester's home router. The hardcoded third-party address also raises the risk that a real external host receives the callback, leaking engagement activity to an unrelated party.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.