PEN-200 · domain
Client-Side Attacks
This domain covers attacking a victim's browser or client application rather than the server directly. On PEN-200 you must build malicious HTA, macro, or library payloads, host them with a web server, and gain code execution when a user opens them. Testing focuses on payload delivery, execution context, and post-exploitation of the client host.
Focused practice
Practice Client-Side Attacks questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Client-Side Attacks
You must craft and host client-side payloads, deliver them to a victim, and catch the resulting shell. The single most important thing is matching the payload to the execution context and having the correct handler or web server already running before the target interacts.
Delivering malicious HTA files that run native commands via mshta.exe on Windows targets
Building Microsoft Office macros that invoke PowerShell or cmd for initial execution
Using Metasploit browser exploits and malicious document handlers for client-side code execution
Identifying XSS input contexts such as HTML body, attributes, and script blocks that allow injection
Watch out for
Common Client-Side Attacks exam traps
- ▸Assuming a malicious file executes without user interaction; most client-side attacks require the victim to open or enable content
- ▸Forgetting to start the matching listener or web server before sending the payload, so no session returns
- ▸Testing XSS in only one context and missing attribute, JavaScript, or URL contexts that need different payload syntax
Question index
All Client-Side Attacks questions (25)
Click any question to see the full explanation, or start a practice session above.
You are building a malicious Microsoft Word document for a phishing campaign. You need the embedded macro to execute automatically as soon as the document is opened, without requiring the victim to click an additional button or dismiss a prompt beyond the initial security warning. Which document element must the macro reside in to achieve automatic execution?
Hard2During a client-side assessment, you find that an application accepts a user-supplied URL parameter and later uses it to redirect the browser away from the site without validating the destination. Which vulnerability class does this behavior represent, and what is its most direct client-side impact?
Easy3You are analyzing a target web application that reflects user input directly into an HTML attribute without proper sanitization. Which vulnerability class should you primarily investigate for exploitation?
Easy4You are conducting a client-side attack using a weaponized Microsoft Office document containing a malicious VBA macro. Which user interaction and application setting combination is required for the macro to execute successfully by default?
Medium5You are performing a client-side attack against a target web application that uses a Content Security Policy (CSP) with the directive `script-src 'self'`. Which TWO techniques are most likely to bypass this CSP and execute JavaScript in a victim’s browser? (Choose two.)
Medium6You are performing a client-side attack against a web application that uses a JSON Web Token (JWT) stored in localStorage for authentication. You have identified a stored XSS vulnerability. Which two actions could you perform to escalate privileges or maintain access? (Choose two.)
Hard7During an authorized penetration test, you discover that a web application’s password reset page reflects the `email` parameter inside a JavaScript string literal with no output encoding. You want to execute arbitrary JavaScript in a victim’s browser when they click a crafted password-reset link. Which payload should you use?
Medium8You are crafting a malicious HTML Application (.hta) to deliver to a Windows user during a phishing engagement. When the file is opened, you want it to execute a PowerShell download cradle that fetches a second-stage payload. Which VBScript construct inside the HTA most directly spawns the hidden PowerShell process?
Hard9You are assessing a web application that reflects user input into an HTML attribute value without quotes, such as `<input value=USER_INPUT>`. Which payload is most likely to execute JavaScript in the victim’s browser?
Hard10During a web application assessment, you discover that the application allows users to upload profile pictures. The server saves these files with their original extensions in a publicly accessible directory. What is the most effective client-side risk associated with this misconfiguration?
Medium11During an authorized penetration test, you want to perform a client-side attack by delivering a malicious HTA file via a phishing email. Which technique is most effective to execute native commands silently when the user opens the file?
Medium12When testing for DOM-based XSS, where should you focus your analysis to find the vulnerable code?
Easy13Refer to the exhibit. ```http HTTP/1.1 200 OK Server: nginx Content-Type: text/html; charset=UTF-8 Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' <html> <body> <h1>Welcome</h1> <script>var token = '12345';</script> </body> </html> ``` Based on the HTTP response headers and body shown in the exhibit, what significant security risk is present regarding client-side attacks?
Hard14You are performing a client-side phishing engagement and need to deliver a malicious payload using an ISO image file. Why is this delivery method often effective against modern Windows security warnings?
Medium15During a penetration test, you want to exploit a client-side vulnerability by sending a link that will execute JavaScript in a victim’s browser when clicked. The target application uses a session cookie without the SameSite attribute. Which attack is most directly enabled by the missing SameSite attribute?
Medium16During an assessment, you identify a Cross-Site Scripting vulnerability that allows you to execute arbitrary JavaScript in the context of a victim user's browser session. What is the primary objective of leveraging this capability against an authenticated user?
Easy17During an authorized internal penetration test, you discover that the corporate proxy does not perform SSL inspection and allows outbound HTTPS to any destination. You need to deliver a client-side payload over HTTPS while evading signature-based network detection. Which technique is most appropriate?
Medium18You are assessing a web application that uses a strict Content Security Policy (CSP) with nonce-based script-src. You discover a reflected XSS vulnerability where your input is inserted into an existing <script> block that already has a valid nonce. Which action would most likely allow your JavaScript to execute despite the CSP?
Hard19Which of the following describes the 'Open Redirect' vulnerability often used in phishing attacks?
Hard20During a penetration test, you discover that a web application uses an outdated version of a JavaScript library that contains a known DOM-based XSS vulnerability. The vulnerability is triggered when a specific URL parameter is processed by the library. Which action would best allow you to demonstrate the impact of this vulnerability to the client?
Easy21During an authorized penetration test, you deliver a malicious script to a victim's browser by exploiting a reflected XSS vulnerability. The script executes in the context of the vulnerable application and silently sends a crafted HTTP request to the application's password-change endpoint. The victim is currently authenticated. Which client-side attack technique are you performing?
Medium22You are testing a web application that sets a session cookie with the HttpOnly flag. You find a reflected XSS vulnerability on a page that does not require authentication. What is the primary impact of exploiting this XSS given the HttpOnly flag?
Hard23When evaluating a web application for Cross-Site Scripting vulnerabilities during a penetration test, which TWO input contexts should you examine because they frequently lead to executable script injection?
Hard24Which property of a URL is most commonly used as a source for DOM-based XSS because it is not sent to the server?
Medium25What is the primary objective of a 'Clickjacking' attack?
EasyOther domains
All PEN-200 exam domains
Frequently asked questions
- What does the Client-Side Attacks domain cover on the PEN-200 exam?
- You must craft and host client-side payloads, deliver them to a victim, and catch the resulting shell. The single most important thing is matching the payload to the execution context and having the correct handler or web server already running before the target interacts.
- How many questions are in this domain?
- This page lists all 25 Client-Side Attacks questions in the PEN-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Client-Side Attacks questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.