Courseiva

PEN-200 · domain

Public Exploits

This domain covers finding, evaluating, adapting, and safely executing public exploit code against target services. PEN-200 tests it through hands-on scenarios: locating a PoC for a known CVE, understanding what the script actually does, adjusting payload options like LHOST, and troubleshooting failures such as connection errors or missing callbacks.

27 questions7 easy12 medium8 hard

Focused practice

Practice Public Exploits questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Public Exploits

A candidate must locate a relevant public exploit, read and understand it, set correct options such as LHOST and target port, and execute it safely. The single most important thing is verifying the exploit matches the target version and that your listener and callback path actually work.

Reading exploit source to identify required arguments, hardcoded paths, and payload type before execution

Setting correct LHOST/LPORT values and matching reverse-shell payloads to the target OS and architecture

Diagnosing failures such as connection refused, closed ports, and blocked outbound callbacks from the target

Adapting PoCs for Windows features like Print Spooler and attacker-hosted SMB shares serving malicious DLLs

Watch out for

Common Public Exploits exam traps

  • ▸Running a public exploit without reading its code or verifying the target version, causing crashes or unintended damage
  • ▸Leaving default LHOST/LPORT or using a payload mismatched to the target architecture, so no shell returns
  • ▸Assuming a reported success means code execution, when the callback was blocked by a firewall or wrong interface

Question index

All Public Exploits questions (27)

Click any question to see the full explanation, or start a practice session above.

1

You download a public exploit archive from an unknown source. Before using it in the PEN-200 lab, which step best protects your own attacking machine from a trojanized exploit?

Easy
2

You are adapting a public Python exploit for a Windows target. The exploit was written for a different architecture and uses a hardcoded payload. Which TWO actions are MOST appropriate to make the exploit work reliably? (Choose two.)

Medium
3

What is the primary danger of using a public exploit without first auditing the source code?

Easy
4

When modifying a public exploit to fit your specific target, which TWO of the following actions are considered best practices? (Choose TWO)

Medium
5

When using Searchsploit, what is the purpose of the '-m' flag?

Easy
6

You have identified an outdated version of a web application running on a target. You found a public exploit script for this version on Exploit-DB. Which step is most critical before executing the exploit script against the target?

Medium
7

A public exploit for a Windows service is written in Python and uses the 'impacket' library. On your Kali attacker machine, running it fails with an ImportError for impacket. What is the most appropriate next step?

Medium
8

You are reviewing a public exploit for a Linux-based web application. The exploit script contains a function that constructs a payload using a format string vulnerability. Which of the following best describes the primary risk of using this exploit without modification on a target with a different libc version?

Hard
9

You download a public exploit from Exploit-DB for a known vulnerability in a web application. Before running it against a client's production server, which action is the MOST appropriate next step?

Easy
10

When an exploit script uses hardcoded memory addresses, why is it likely to fail on a modern target system?

Hard
11

Which repository is generally considered the most reliable starting point for finding verified, community-contributed public exploits during an OSCP assessment?

Easy
12

A public exploit for a Linux service includes a compiled payload that connects back to a hardcoded IP address. You need to adapt it for your PEN-200 engagement. Which TWO actions are most appropriate? (Choose two.)

Hard
13

Why is it important to use a local listener that matches the protocol expected by your exploit's payload?

Medium
14

You are reviewing a public exploit for a Linux-based web application. The exploit is a Python script that uses a hardcoded offset to overwrite a return address, and it includes a comment stating it was tested on a specific kernel version. Your target runs a different kernel but the same application version. After running the exploit, the service crashes but no shell is obtained. Which action is the MOST appropriate next step?

Hard
15

You have found a Python exploit that uses the 'requests' library but your target machine only has standard Python installed. What is your best course of action?

Medium
16

Which resource is most reliable for verifying that a public exploit is legitimate and does not contain hidden backdoors?

Easy
17

During a PEN-200 lab engagement you locate a public exploit for a web application running on the target. The exploit's banner string is 'Mozilla/5.0' and the script appends the payload to a URL parameter. Before running it against the target, which action best reduces the risk of unintended side effects on the production web service?

Medium
18

Refer to the exhibit. You identify an Apache 2.4.49 vulnerability and locate the exploit. After reviewing the exploit code, you realize it requires a specific input format to trigger the path traversal. What is the most effective way to verify the vulnerability without crashing the server?

Hard
19

You have identified a vulnerable service using an outdated version of a CMS. You successfully locate a public exploit script on GitHub. What is the most critical first step before running this script against your target?

Medium
20

You are adapting a public exploit whose payload is a reverse shell. The exploit runs and the service reports success, but your netcat listener never receives a connection. Which cause is most likely?

Hard
21

Refer to the exhibit. You are running a public exploit, but it fails with a 'Connection refused' error. What should you investigate first?

Hard
22

You are assessing a Windows host and discover the Print Spooler service is running. You locate a public PoC for CVE-2021-1675 that requires an attacker-controlled SMB share hosting a malicious DLL. You want to execute the exploit from your Kali machine against the target. Which action must you take FIRST before running the PoC?

Medium
23

Why might a public exploit for a specific service fail to execute even when the service version matches the vulnerability description exactly?

Medium
24

During an internal assessment, you find a public exploit for a Jenkins script console vulnerability. The exploit sends a Groovy script to /script via a POST request. When you run it, the server returns HTTP 403. The Jenkins version matches the vulnerable range, and the endpoint is reachable. Which is the MOST likely reason the exploit fails?

Hard
25

During a PEN-200 lab exercise, you find a public exploit for a Windows service. The exploit source contains a hardcoded return address of 0x41414141 and a comment that it was tested against a different Windows build with ASLR disabled. What should you do before running it against your target?

Medium
26

When analyzing a public exploit, which TWO elements should you specifically look for to understand its networking behavior? (Choose TWO)

Medium
27

You download a public exploit for a known vulnerability from an untrusted source. Before running it against a client's production system, what is the most important action to take?

Easy

Frequently asked questions

What does the Public Exploits domain cover on the PEN-200 exam?
A candidate must locate a relevant public exploit, read and understand it, set correct options such as LHOST and target port, and execute it safely. The single most important thing is verifying the exploit matches the target version and that your listener and callback path actually work.
How many questions are in this domain?
This page lists all 27 Public Exploits questions in the PEN-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Public Exploits questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
offsec-oscp OFFSEC-OSCP public exploits Practice Questions