PEN-200 · domain
Public Exploits
This domain covers finding, evaluating, adapting, and safely executing public exploit code against target services. PEN-200 tests it through hands-on scenarios: locating a PoC for a known CVE, understanding what the script actually does, adjusting payload options like LHOST, and troubleshooting failures such as connection errors or missing callbacks.
Focused practice
Practice Public Exploits questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Public Exploits
A candidate must locate a relevant public exploit, read and understand it, set correct options such as LHOST and target port, and execute it safely. The single most important thing is verifying the exploit matches the target version and that your listener and callback path actually work.
Reading exploit source to identify required arguments, hardcoded paths, and payload type before execution
Setting correct LHOST/LPORT values and matching reverse-shell payloads to the target OS and architecture
Diagnosing failures such as connection refused, closed ports, and blocked outbound callbacks from the target
Adapting PoCs for Windows features like Print Spooler and attacker-hosted SMB shares serving malicious DLLs
Watch out for
Common Public Exploits exam traps
- ▸Running a public exploit without reading its code or verifying the target version, causing crashes or unintended damage
- ▸Leaving default LHOST/LPORT or using a payload mismatched to the target architecture, so no shell returns
- ▸Assuming a reported success means code execution, when the callback was blocked by a firewall or wrong interface
Question index
All Public Exploits questions (27)
Click any question to see the full explanation, or start a practice session above.
You download a public exploit archive from an unknown source. Before using it in the PEN-200 lab, which step best protects your own attacking machine from a trojanized exploit?
Easy2You are adapting a public Python exploit for a Windows target. The exploit was written for a different architecture and uses a hardcoded payload. Which TWO actions are MOST appropriate to make the exploit work reliably? (Choose two.)
Medium3What is the primary danger of using a public exploit without first auditing the source code?
Easy4When modifying a public exploit to fit your specific target, which TWO of the following actions are considered best practices? (Choose TWO)
Medium5When using Searchsploit, what is the purpose of the '-m' flag?
Easy6You have identified an outdated version of a web application running on a target. You found a public exploit script for this version on Exploit-DB. Which step is most critical before executing the exploit script against the target?
Medium7A public exploit for a Windows service is written in Python and uses the 'impacket' library. On your Kali attacker machine, running it fails with an ImportError for impacket. What is the most appropriate next step?
Medium8You are reviewing a public exploit for a Linux-based web application. The exploit script contains a function that constructs a payload using a format string vulnerability. Which of the following best describes the primary risk of using this exploit without modification on a target with a different libc version?
Hard9You download a public exploit from Exploit-DB for a known vulnerability in a web application. Before running it against a client's production server, which action is the MOST appropriate next step?
Easy10When an exploit script uses hardcoded memory addresses, why is it likely to fail on a modern target system?
Hard11Which repository is generally considered the most reliable starting point for finding verified, community-contributed public exploits during an OSCP assessment?
Easy12A public exploit for a Linux service includes a compiled payload that connects back to a hardcoded IP address. You need to adapt it for your PEN-200 engagement. Which TWO actions are most appropriate? (Choose two.)
Hard13Why is it important to use a local listener that matches the protocol expected by your exploit's payload?
Medium14You are reviewing a public exploit for a Linux-based web application. The exploit is a Python script that uses a hardcoded offset to overwrite a return address, and it includes a comment stating it was tested on a specific kernel version. Your target runs a different kernel but the same application version. After running the exploit, the service crashes but no shell is obtained. Which action is the MOST appropriate next step?
Hard15You have found a Python exploit that uses the 'requests' library but your target machine only has standard Python installed. What is your best course of action?
Medium16Which resource is most reliable for verifying that a public exploit is legitimate and does not contain hidden backdoors?
Easy17During a PEN-200 lab engagement you locate a public exploit for a web application running on the target. The exploit's banner string is 'Mozilla/5.0' and the script appends the payload to a URL parameter. Before running it against the target, which action best reduces the risk of unintended side effects on the production web service?
Medium18Refer to the exhibit. You identify an Apache 2.4.49 vulnerability and locate the exploit. After reviewing the exploit code, you realize it requires a specific input format to trigger the path traversal. What is the most effective way to verify the vulnerability without crashing the server?
Hard19You have identified a vulnerable service using an outdated version of a CMS. You successfully locate a public exploit script on GitHub. What is the most critical first step before running this script against your target?
Medium20You are adapting a public exploit whose payload is a reverse shell. The exploit runs and the service reports success, but your netcat listener never receives a connection. Which cause is most likely?
Hard21Refer to the exhibit. You are running a public exploit, but it fails with a 'Connection refused' error. What should you investigate first?
Hard22You are assessing a Windows host and discover the Print Spooler service is running. You locate a public PoC for CVE-2021-1675 that requires an attacker-controlled SMB share hosting a malicious DLL. You want to execute the exploit from your Kali machine against the target. Which action must you take FIRST before running the PoC?
Medium23Why might a public exploit for a specific service fail to execute even when the service version matches the vulnerability description exactly?
Medium24During an internal assessment, you find a public exploit for a Jenkins script console vulnerability. The exploit sends a Groovy script to /script via a POST request. When you run it, the server returns HTTP 403. The Jenkins version matches the vulnerable range, and the endpoint is reachable. Which is the MOST likely reason the exploit fails?
Hard25During a PEN-200 lab exercise, you find a public exploit for a Windows service. The exploit source contains a hardcoded return address of 0x41414141 and a comment that it was tested against a different Windows build with ASLR disabled. What should you do before running it against your target?
Medium26When analyzing a public exploit, which TWO elements should you specifically look for to understand its networking behavior? (Choose TWO)
Medium27You download a public exploit for a known vulnerability from an untrusted source. Before running it against a client's production system, what is the most important action to take?
EasyOther domains
All PEN-200 exam domains
Frequently asked questions
- What does the Public Exploits domain cover on the PEN-200 exam?
- A candidate must locate a relevant public exploit, read and understand it, set correct options such as LHOST and target port, and execute it safely. The single most important thing is verifying the exploit matches the target version and that your listener and callback path actually work.
- How many questions are in this domain?
- This page lists all 27 Public Exploits questions in the PEN-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Public Exploits questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.