PEN-200 Public Exploits Practice Question
A public exploit for a Windows service is written in Python and uses the 'impacket' library. On your Kali attacker machine, running it fails with an ImportError for impacket. What is the most appropriate next step?
⚠ Common exam trap
The trap here is treating a missing Python dependency as a reason to rewrite or downgrade the exploit, when the correct fix is simply installing the library.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install the impacket package on Kali using the distribution's package manager or pip, then rerun the exploit.
The ImportError indicates a missing Python dependency, not a flaw in the exploit. Installing impacket through the package manager or pip restores the required protocol library and lets the script run as written. Rewriting the exploit, changing interpreter versions, or copying library folders all introduce new problems without addressing the missing package.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Copy the impacket directory from a different tool's installation folder into the exploit's working directory.
Why it's wrong here
Copying an arbitrary impacket directory risks version mismatches and missing compiled dependencies, which can produce subtle protocol errors rather than a clean fix. It also bypasses the package manager that would track, update, and verify the library, leaving the environment in an inconsistent state that is hard to troubleshoot later.
- ✗
Rewrite the exploit to use raw sockets so no external library is required.
Why it's wrong here
Rewriting to raw sockets discards the SMB or RPC handling that impacket provides and would require reimplementing complex protocol logic, which is error-prone and unnecessary. The missing dependency is a solvable environment issue, so replacing the library with hand-rolled code adds risk without addressing the actual cause of the failure.
- ✓
Install the impacket package on Kali using the distribution's package manager or pip, then rerun the exploit.
Why this is correct
The ImportError means the impacket library is simply absent from the Python environment. Installing it through the distribution package manager or pip resolves the dependency directly, after which the exploit can run unchanged. This is the minimal, correct fix because the exploit's logic is not the problem.
- ✗
Run the exploit with Python 2 instead of Python 3 to avoid the import error.
Why it's wrong here
Switching interpreter versions does not install impacket; if the library is missing for Python 3 it is likely missing for Python 2 as well. Modern impacket releases target Python 3, so forcing Python 2 may introduce syntax and compatibility failures while leaving the original missing-dependency problem unresolved.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.