Courseiva

PEN-200 · domain

scenario questions

Practise OffSec PEN-200 / OSCP Concepts scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

285 questions64 easy147 medium74 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (285)

Click any question to see the full explanation, or start a practice session above.

1

During enumeration you discover a DNS server that allows zone transfers to any client. What is the most valuable outcome of performing a successful AXFR against this server?

Hard
2

You are tasked with delivering a Meterpreter payload to a Windows Server 2019 target protected by a next-generation antivirus that performs userland API hooking on NtAllocateVirtualMemory and NtProtectVirtualMemory. Your current C loader uses these APIs directly and is detected. Which technique is most appropriate to bypass the userland hooks without requiring kernel-level privileges?

Hard
3

When performing a password spraying attack, why is it considered best practice to use a single common password against many accounts rather than many passwords against one account?

Easy
4

Based on the exhibit, what is the primary risk if your shellcode contains the byte \x0d?

Medium
5

A penetration tester modifies a known exploit's payload by changing variable names and adding junk instructions. Despite these changes, the antivirus software still flags the file as 'Trojan.Generic' immediately upon being written to disk. What is the most likely reason for this detection?

Easy
6

Why is it often effective to check for 'Capabilities' on Linux binaries when SUID is not present?

Medium
7

You are building a malicious Microsoft Word document for a phishing campaign. You need the embedded macro to execute automatically as soon as the document is opened, without requiring the victim to click an additional button or dismiss a prompt beyond the initial security warning. Which document element must the macro reside in to achieve automatic execution?

Hard
8

You download a public exploit archive from an unknown source. Before using it in the PEN-200 lab, which step best protects your own attacking machine from a trojanized exploit?

Easy
9

When auditing a Windows host for privilege escalation vectors during a PEN-200 assessment, you discover that the machine has AlwaysInstallElevated enabled in the Windows Registry. Which TWO conditions must be verified simultaneously to successfully weaponize this misconfigured policy?

Hard
10

During post-exploitation on a Linux target, you discover a binary with the SUID bit set owned by root. Running 'strings' on the binary reveals it calls 'system("ps")' without specifying an absolute path. Which of the following techniques is most likely to allow you to escalate privileges by exploiting this behavior?

Medium
11

Which of the following is a common symptom of a Command Injection vulnerability?

Easy
12

A penetration tester is investigating scheduled tasks for potential privilege escalation. Which TWO conditions must be met for a scheduled task to be successfully exploited for gaining SYSTEM privileges?

Hard
13

Which attack involves an attacker capturing NTLM authentication traffic from a user and relaying it to another machine to gain unauthorized access?

Medium
14

Which of the following describes the primary difference between a Golden Ticket and a Silver Ticket attack in an Active Directory environment?

Easy
15

When performing SSH dynamic port forwarding with the -D flag, what is the primary benefit compared to local port forwarding (-L)?

Easy
16

You are developing a proof-of-concept exploit for a Linux x86 UDP service that crashes when sent a long string of 'B's. Before attempting to redirect execution, you want to determine whether the crash gives you control of the instruction pointer. Which single action best confirms that the saved return address on the stack has been overwritten?

Easy
17

Which of the following describes the danger of a service that runs as 'LocalSystem' but does not have the 'Interactive' flag enabled?

Hard
18

You have captured a NetNTLMv2 hash during a man-in-the-middle attack. What is the most effective approach to use this hash to gain access to the target machine?

Medium
19

You are assessing a web application that uses a relational database backend. During manual testing, you suspect a UNION-based SQL injection vulnerability in a product category parameter. Which two of the following steps are necessary to successfully extract data using a UNION-based SQL injection attack? (Choose two.)

Medium
20

Why is using the default 'msfvenom' encoders like 'shikata_ga_nai' often insufficient for bypassing modern antivirus solutions?

Easy
21

You are testing a Java-based web application that uses the Spring framework. The application has an endpoint /api/users/{id} that returns user details in JSON. When you request /api/users/123, you receive your own details. You then request /api/users/124 and receive another user's details. The application uses a session cookie but does not implement any role-based checks on this endpoint. What is the MOST appropriate next step to demonstrate the impact of this vulnerability?

Hard
22

You are adapting a public Python exploit for a Windows target. The exploit was written for a different architecture and uses a hardcoded payload. Which TWO actions are MOST appropriate to make the exploit work reliably? (Choose two.)

Medium
23

What is the primary danger of using a public exploit without first auditing the source code?

Easy
24

Which Linux kernel feature, if misconfigured or outdated, allows an unprivileged user to gain root access by exploiting a vulnerability in the handling of user namespaces?

Medium
25

When performing a kernel exploit for privilege escalation, what is the most significant risk to the stability of the target system?

Hard
26

You have compromised a domain user account and discovered that the domain controller is running Windows Server 2016. You want to extract the KRBTGT account hash to create a Golden Ticket. Which two conditions are necessary to successfully perform a DCSync attack to obtain the KRBTGT hash? (Choose two.)

Hard
27

During a penetration test, you obtain a Kerberos TGS-REP hash for a service account. You want to crack this hash offline to recover the service account's password. Which of the following tools is most appropriate for this task?

Medium
28

You are performing reconnaissance and want to identify if a target website uses a specific CMS like WordPress. What is the most effective approach?

Medium
29

During a penetration test on a Windows Server 2019 host, you obtain a low-privileged shell as user 'webuser'. You run 'whoami /priv' and observe that the account has SeImpersonatePrivilege enabled. Which exploitation technique is most directly applicable?

Easy
30

A penetration tester discovers that the current user can write to a script located in /opt/backup/ that is executed every minute by a cron job running as root. The script has permissions `-rwxr-xr-x 1 root root`. What is the MOST reliable way to escalate privileges?

Medium
31

Which of the following describes the risk associated with using a password manager that lacks a master password and relies solely on local file encryption?

Hard
32

During a client-side assessment, you find that an application accepts a user-supplied URL parameter and later uses it to redirect the browser away from the site without validating the destination. Which vulnerability class does this behavior represent, and what is its most direct client-side impact?

Easy
33

You have captured an NTLM hash of a domain user. Why is performing a Pass-the-Hash (PtH) attack often more effective than attempting to crack the hash for the cleartext password?

Medium
34

You are exploiting a 32-bit Linux buffer overflow and have overwritten EIP with the address of a `JMP ESP` instruction located in a non-ASLR module. However, when you run the exploit, the program crashes with a segmentation fault, and no shell is obtained. You verify that the offset is correct and the JMP ESP address is accurate. What is the most likely reason for the failure?

Hard
35

When analyzing the memory of a compromised system, you find that your shellcode is being detected by behavioral monitoring. What is the most effective approach to reduce the likelihood of detection by EDR systems during process injection?

Medium
36

During a Linux privilege escalation assessment, you obtain a low-privileged shell as user 'student'. You run 'id' and see the user belongs to the 'docker' group. Which command will most reliably escalate to root on this host?

Medium
37

You are analyzing a target web application that reflects user input directly into an HTML attribute without proper sanitization. Which vulnerability class should you primarily investigate for exploitation?

Easy
38

A tester is targeting a Windows machine and notices that a specific legitimate application regularly looks for a COM object that is missing from the HKEY_CURRENT_USER (HKCU) registry hive, eventually falling back to HKEY_LOCAL_MACHINE (HKLM). How can this be exploited for evasion?

Medium
39

You have compromised a Linux host and extracted the /etc/shadow file. The file contains a hash starting with `$6$`. Which hashing algorithm does this prefix indicate?

Easy
40

You have obtained a low-privileged shell on a Windows Server 2016 machine. While enumerating, you notice that the 'SeImpersonatePrivilege' is enabled for your user account. You also find that the machine is running a service with a named pipe '\\.\pipe\svcctl' that is accessible. Which tool is specifically designed to exploit this privilege to escalate to SYSTEM?

Hard
41

When modifying a public exploit to fit your specific target, which TWO of the following actions are considered best practices? (Choose TWO)

Medium
42

When using Searchsploit, what is the purpose of the '-m' flag?

Easy
43

You are conducting a client-side attack using a weaponized Microsoft Office document containing a malicious VBA macro. Which user interaction and application setting combination is required for the macro to execute successfully by default?

Medium
44

Which THREE 'Living off the Land' (LotL) binaries are frequently used by penetration testers to download or execute malicious code while bypassing basic antivirus restrictions?

Medium
45

You have identified an outdated version of a web application running on a target. You found a public exploit script for this version on Exploit-DB. Which step is most critical before executing the exploit script against the target?

Medium
46

Refer to the exhibit. You have scanned a target and obtained these results. Which step is most logical to perform next to effectively enumerate the web service?

Medium
47

You are enumerating a Linux host and discover TCP port 2049 open. You need to determine what is being exported and to whom before deciding on any exploitation path. Which action most directly answers that question?

Medium
48

Which of the following describes a stored Cross-Site Scripting (XSS) attack?

Easy
49

During a penetration test against a web application, you identify a parameter vulnerable to Blind SQL Injection. The backend database is Microsoft SQL Server, and the application does not return any error messages or query results. Which technique should you use to exfiltrate data character by character based on application behavior?

Medium
50

You have obtained credentials for a domain user and want to enumerate Active Directory to find misconfigured ACLs that allow privilege escalation. You need to collect data that maps relationships between users, groups, computers, and sessions, and you want to visualize shortest paths to Domain Admin. Which tool and collection method best fits this requirement?

Medium
51

Which THREE of the following are considered 'active' reconnaissance techniques, as opposed to passive techniques?

Hard
52

During an authorized web application assessment, you discover a search page that reflects the query parameter directly into the HTML response body without encoding. You want to confirm the presence of a reflected cross-site scripting vulnerability using a minimal, non-destructive payload. Which of the following payloads is most likely to execute JavaScript in a victim's browser when injected into the vulnerable parameter?

Medium
53

Which TWO methods are effective for obfuscating a PowerShell script to bypass AMSI without modifying the underlying system DLLs?

Medium
54

Which TWO of the following techniques are most effective for enumerating SMB shares on a Windows host during a penetration test?

Medium
55

A junior penetration tester is preparing a payload for a Windows 10 target and wants to avoid signature-based detection by changing the binary's appearance without altering its functionality. Which technique is specifically designed to achieve this?

Easy
56

While auditing a web application, you identify an endpoint that retrieves profile images via a URL parameter: 'image.php?file=profile.jpg'. Changing the parameter to 'image.php?file=/etc/passwd' returns the contents of the system password file. Which vulnerability is present, and what is the primary risk?

Medium
57

An operator is analyzing why a compiled C# stager payload was flagged immediately by Windows Defender despite having a completely unique cryptographic hash. Which AV detection mechanism is most likely responsible for flagging the binary based on internal structure rather than known file signatures?

Medium
58

During an internal penetration test, you obtain an NTDS.dit file and the associated SYSTEM registry hive. You need to crack the NTLM password hashes extracted from these files using Hashcat. Which command-line argument correctly specifies the hash type for standard Windows NTLM hashes?

Medium
59

When using SSH tunneling, what is the primary security risk of using the '-R' flag in a multi-user environment?

Medium
60

Refer to the exhibit. The 'find' binary has the SUID bit set. How can you leverage this to gain a root shell?

Hard
61

During a PEN-200 lab engagement, a tester delivers a custom C# implant compiled with csc.exe. Windows Defender's real-time protection immediately quarantines the executable at rest on disk, before any process is created. The tester wants to keep the same implant logic but reduce static file-based detection. Which approach best addresses this specific detection stage?

Medium
62

When evaluating an antivirus solution's effectiveness, what is the primary difference between signature-based detection and behavioral-based detection?

Easy
63

During an external penetration test, you discover a web server hosting multiple virtual hosts. You want to enumerate additional hostnames that resolve to the same IP address without triggering intrusion detection systems. Which technique is most appropriate?

Hard
64

During an internal penetration test, you have captured network traffic and identified a host that responds on TCP port 445. You want to gather detailed information about the SMB service, including the operating system version, NetBIOS name, and domain, without authenticating. Which Nmap NSE script is most appropriate for this task?

Medium
65

You have successfully found the exact offset to overwrite the EIP register and identified a reliable JMP ESP instruction inside an unProtected DLL. However, when your shellcode executes, the program immediately crashes with an access violation before launching the payload. Inspection reveals that the stack pointer (ESP) points directly to the beginning of your shellcode, but the memory page housing the stack lacks execution permissions. Which modern defense mechanism is preventing your exploit from succeeding?

Medium
66

What is the primary security risk of an application that fails to properly validate the 'Content-Type' header during a file upload process?

Medium
67

You are performing web enumeration against a target application and want to discover hidden directories, backup files, and administrative interfaces that are not linked from the visible pages. Which two approaches are most appropriate for this goal? (Choose two.)

Medium
68

Refer to the exhibit. As an attacker attempting to brute-force a web login, why is receiving this specific error message beneficial to your engagement?

Medium
69

Refer to the exhibit. The command failed to crack the NTLM hash despite using a comprehensive wordlist. What is the most likely reason for this result?

Medium
70

You are performing a client-side attack against a target web application that uses a Content Security Policy (CSP) with the directive `script-src 'self'`. Which TWO techniques are most likely to bypass this CSP and execute JavaScript in a victim’s browser? (Choose two.)

Medium
71

Which file is essential for auditing to determine which users have been granted sudo privileges?

Easy
72

During an internal assessment you receive a scope that lists a /24 subnet but explicitly forbids any traffic that could cause service disruption. You need to identify live hosts and open TCP ports while keeping the scan as quiet and non-intrusive as possible. Which single Nmap invocation best matches these constraints?

Hard
73

You are testing a Java web application that stores user-supplied SVG avatars. The application sanitizes SVG files by stripping `<script>` tags, then serves them from the same origin with `Content-Type: image/svg+xml`. When a victim views another user's profile, the browser renders the SVG inline. Which technique most reliably achieves script execution in the victim's session despite the sanitizer?

Hard
74

When performing reconnaissance on an unknown network, you discover a service running on port 161. What is the most appropriate action to take to determine if this service can be abused?

Hard
75

An ethical hacker wants to evade signature-based detection while developing a custom reverse shell loader for a PEN-200 lab assignment. Which technique fundamentally alters the binary's byte signatures without modifying its core execution logic or breaking the payload?

Medium
76

While enumerating a Linux host, you notice that the `passwd` command has the SUID bit set and is owned by root. You recall that SUID binaries run with the privileges of the file owner. Which of the following is the most direct way to leverage this to gain root access?

Easy
77

You compromise a Windows host and dump local account hashes with secretsdump, obtaining the NTLM hash of a local administrator. That same local administrator password was reused across every workstation in the environment. Which technique most directly allows lateral movement to other hosts using that hash without ever recovering the cleartext password?

Hard
78

What is the primary goal of utilizing an intercepting proxy during a web application penetration test?

Easy
79

Refer to the exhibit. An examiner attempts to use raw msfvenom output directly in a custom C template for a PEN-200 lab assignment, but the payload is instantly detected. Why is generating raw msfvenom output generally ineffective for antivirus evasion without further modification?

Hard
80

Which THREE of the following are valid techniques for achieving persistence within an Active Directory environment?

Hard
81

You are enumerating a Linux host and find that UDP port 161 responds to SNMP queries with the community string 'public'. Which action yields the most useful reconnaissance data for planning later exploitation?

Hard
82

You have gained a low-privileged shell on a Windows system and discovered a service running as 'LocalSystem' with an unquoted executable path containing spaces. Which action is the most direct way to escalate privileges?

Medium
83

You are performing a client-side attack against a web application that uses a JSON Web Token (JWT) stored in localStorage for authentication. You have identified a stored XSS vulnerability. Which two actions could you perform to escalate privileges or maintain access? (Choose two.)

Hard
84

During a web application assessment, you identify a blind SQL injection vulnerability in a cookie parameter. The backend database is PostgreSQL. You want to determine the first character of the database name using a time-based injection. Which of the following payloads would correctly test if the first character is 'p' by causing a 5-second delay?

Medium
85

During an authorized penetration test, you discover that a web application’s password reset page reflects the `email` parameter inside a JavaScript string literal with no output encoding. You want to execute arbitrary JavaScript in a victim’s browser when they click a crafted password-reset link. Which payload should you use?

Medium
86

During an internal penetration test you compromise a domain-joined workstation and recover a user's NTLMv2 hash via a forced authentication attempt. SMB signing is enforced on all servers, and the client will not initiate outbound SMB connections. You want to crack the credential offline rather than relay it. Which approach is most appropriate?

Medium
87

A junior penetration tester is preparing a payload for a Windows 10 target with Windows Defender enabled. The tester wants to avoid writing the payload to disk and decides to use a PowerShell one-liner that downloads and executes a script in memory. Which PowerShell feature allows the script to be executed directly from a downloaded string without saving it to a file?

Easy
88

A public exploit for a Windows service is written in Python and uses the 'impacket' library. On your Kali attacker machine, running it fails with an ImportError for impacket. What is the most appropriate next step?

Medium
89

During a Windows privilege escalation assessment, you encounter a service with an unquoted service path: 'C:\Program Files\Vulnerable Service\service.exe'. The service runs as LocalSystem. Which TWO conditions must be true for you to successfully exploit this unquoted service path? (Choose two.)

Hard
90

You have an SSH dynamic forward running on port 1080 to a compromised Linux host, and you want to use it with a tool that supports SOCKS5 natively. Which environment variable or configuration is most appropriate to direct the tool through the proxy without using proxychains?

Medium
91

You are performing a network scan on a client segment and notice that a host responds to ICMP echo requests but shows all TCP ports as 'filtered' when using Nmap. Which conclusion is most accurate?

Medium
92

You are enumerating a Linux target and discover that TCP port 2049 is open. You run `showmount -e 192.168.1.100` and see that the `/home` directory is exported to everyone. What is the most significant security risk this configuration presents?

Medium
93

You are reviewing a public exploit for a Linux-based web application. The exploit script contains a function that constructs a payload using a format string vulnerability. Which of the following best describes the primary risk of using this exploit without modification on a target with a different libc version?

Hard
94

You download a public exploit from Exploit-DB for a known vulnerability in a web application. Before running it against a client's production server, which action is the MOST appropriate next step?

Easy
95

In the context of password cracking, what is a 'rule' in tools like Hashcat or John the Ripper?

Easy
96

You are crafting a malicious HTML Application (.hta) to deliver to a Windows user during a phishing engagement. When the file is opened, you want it to execute a PowerShell download cradle that fetches a second-stage payload. Which VBScript construct inside the HTA most directly spawns the hidden PowerShell process?

Hard
97

During an internal penetration test, you compromise a Linux host that has outbound SSH access to your attacking machine but cannot directly reach an internal Windows server on 10.10.10.5:445. You need to forward SMB traffic through the compromised host so that your local tools can connect to 10.10.10.5:445. Which command should you run from your attacking machine to create the required tunnel?

Medium
98

During a stack-based buffer overflow exploitation attempt in a Win32 environment, you notice that your shellcode execution fails because certain memory addresses contain null bytes (0x00). Which component of the exploit development process is primarily responsible for identifying and mitigating bad characters?

Medium
99

Which THREE of the following are essential steps when manually exploiting a stack-based buffer overflow?

Medium
100

You have successfully obtained a NTLM hash dump from a domain controller. You intend to perform a pass-the-hash attack to move laterally. What is the most critical requirement for this technique to succeed in a modern Windows environment?

Medium
101

You have obtained a copy of a Windows SAM file from a compromised host. You want to extract the NTLM hashes for offline cracking. Which of the following tools is specifically designed for this task?

Easy
102

While pivoting through a compromised host, you want to route an Impacket tool through a SOCKS proxy you established with SSH dynamic forwarding. The tool does not support SOCKS natively. Which approach allows the Impacket tool to use the proxy correctly?

Medium
103

Which TWO of the following statements correctly describe the function of a NOP sled in a buffer overflow exploit?

Hard
104

During enumeration of a Windows host, you run `whoami /priv` and see that the current user has SeImpersonatePrivilege enabled. You have also uploaded a custom executable to C:\Windows\Temp. Which privilege escalation technique is most directly applicable in this situation?

Medium
105

You are assessing a web application that reflects user input into an HTML attribute value without quotes, such as `<input value=USER_INPUT>`. Which payload is most likely to execute JavaScript in the victim’s browser?

Hard
106

During an internal penetration test, you compromise a Linux machine that acts as a pivot host, but the target internal web server only permits HTTP traffic from localhost. Which local port forwarding syntax allows you to securely access this web application via your attacking machine?

Medium
107

A penetration tester has written a C# loader that reads shellcode from a file, allocates memory with VirtualAlloc using PAGE_EXECUTE_READWRITE, and executes it via CreateThread. The loader is not detected by static antivirus signatures, but when run on a Windows 10 host with Microsoft Defender's real-time protection enabled, the process is terminated shortly after execution begins. The tester suspects behavior-based detection. Which modification is MOST likely to prevent this behavioral detection while preserving execution?

Medium
108

Which of the following describes the 'GPP Password' vulnerability?

Medium
109

A penetration tester is building a custom shellcode runner in C for a PEN-200 lab. The compiled loader is being flagged by static analysis before execution. The tester wants to modify the loader's source so the resulting binary is less likely to match signatures, without changing the shellcode's behavior. Which two changes best serve this goal? (Choose two.)

Medium
110

During an internal assessment, you compromise a Windows host that can reach a segmented network. You want to run a SOCKS proxy on the compromised Windows host so that your Kali tools can reach internal targets through it. Which tool is specifically designed for this purpose and commonly used in PEN-200 scenarios?

Easy
111

You are exploiting a buffer overflow in a 32-bit Windows application and have overwritten EIP with a JMP ESP address. However, when the shellcode executes, it fails to establish a reverse shell, and the application crashes. You suspect that the shellcode contains bad characters. Which of the following is the most effective way to identify bad characters in the shellcode?

Hard
112

What is the primary purpose of using 'accesschk' during the enumeration phase of Windows privilege escalation?

Easy
113

What is the primary objective of an 'AS-REP Roasting' attack?

Easy
114

Given the exhibit, why might using the address 0x00401020 to overwrite EIP be ineffective for shellcode execution?

Hard
115

You have a low-privileged shell on a Windows 10 workstation and discover that the folder 'C:\ProgramData\Updater' has weak permissions: the 'Users' group has 'Write' and 'Modify' rights. A scheduled task runs 'C:\ProgramData\Updater\update.exe' every hour as SYSTEM. What is the most reliable way to escalate privileges?

Medium
116

You have compromised a Linux system and extracted the /etc/shadow file. The root account's hash is prefixed with $6$. Which of the following statements is true regarding cracking this hash?

Hard
117

When an exploit script uses hardcoded memory addresses, why is it likely to fail on a modern target system?

Hard
118

During an internal penetration test, you compromise a Windows host that has two network interfaces: one on your attack network (10.10.10.0/24) and one on a restricted internal network (172.16.5.0/24). You need to scan a web server at 172.16.5.20:80 from your Kali machine. You decide to use SSH dynamic port forwarding. Which command should you run on your Kali machine to create a SOCKS proxy listening on localhost port 1080 through the compromised Windows host (10.10.10.15) using SSH?

Medium
119

Which repository is generally considered the most reliable starting point for finding verified, community-contributed public exploits during an OSCP assessment?

Easy
120

Refer to the exhibit. What is the primary vulnerability shown here?

Medium
121

Which tool is primarily used to perform BloodHound data collection to map out attack paths within an Active Directory environment?

Easy
122

You have identified a stack-based buffer overflow in a Windows application. The application is compiled with SafeSEH, and you have confirmed that no SafeSEH-protected exception handlers can be overwritten. However, you notice that the stack is executable. You need to redirect execution to your shellcode. Which technique is most likely to succeed?

Hard
123

During a buffer overflow exploit development, you need to determine the exact number of bytes required to overwrite the EIP register. Which method is most commonly used to find this offset?

Easy
124

Given the exhibit, what is the correct strategy to redirect control flow to the shellcode?

Medium
125

While debugging a custom TCP server running on a Windows target, you send an overly long string of 'A' characters and notice that the application crashes, overwriting the EIP register with 0x41414141. What does this specific hex value indicate about the state of the debugger?

Easy
126

You are conducting a penetration test and have obtained a list of usernames. You want to perform a password spray against an OWA (Outlook Web Access) portal. Which tool is specifically designed to automate password spraying against OWA while respecting lockout policies?

Medium
127

During a red team engagement, a tester writes a C# loader that calls the Win32 API function VirtualAllocEx to allocate memory in a remote process, writes shellcode, and creates a remote thread. The loader compiles and runs, but the endpoint's EDR blocks it before the remote thread executes. The tester confirms the EDR is hooking user-mode API functions in ntdll.dll. Which approach most directly avoids the user-mode hooks that triggered the block?

Hard
128

Which of the following describes the security benefit of the 'HttpOnly' flag shown in the exhibit?

Medium
129

You are performing active reconnaissance against a web server and want to identify hidden directories and files that may not be linked from the main site. Which two techniques are most appropriate for this goal? (Choose two.)

Hard
130

During an internal Active Directory assessment, you have compromised a standard domain user account. You run BloodHound and identify that this user has the 'GenericAll' permission over a computer object named WEB01. You want to leverage this permission to compromise WEB01 and obtain administrative access to it. Which of the following is the most direct and reliable technique to achieve this?

Hard
131

During a web application assessment, you discover that the application allows users to upload profile pictures. The server saves these files with their original extensions in a publicly accessible directory. What is the most effective client-side risk associated with this misconfiguration?

Medium
132

During an authorized penetration test, you want to perform a client-side attack by delivering a malicious HTA file via a phishing email. Which technique is most effective to execute native commands silently when the user opens the file?

Medium
133

You have compromised a Windows host and obtained credentials for a low-privileged domain user. You discover that this user has 'GenericWrite' permissions on a computer object in Active Directory. Which attack technique can you use to escalate privileges on that computer?

Medium
134

Why might a penetration tester use a 'jump host' when attempting to access an internal network segment?

Easy
135

You are developing an exploit for a 32-bit Windows application that contains a stack-based buffer overflow. After overwriting EIP with a JMP ESP address, you place a payload that includes a reverse shell. During testing, the shell connects back successfully, but the application crashes immediately after the shell terminates. What is the most likely cause of the crash?

Medium
136

You are performing a penetration test against a web application that uses a Linux backend. You discover a file inclusion vulnerability in the 'page' parameter: 'index.php?page=home.php'. You attempt to include '/etc/passwd' using path traversal, but the application appends '.php' to the input. You try 'page=../../../../etc/passwd%00' but the null byte is blocked. Which of the following techniques is most likely to allow you to read the '/etc/passwd' file?

Hard
137

A penetration tester has obtained a low-privilege shell on a Windows 10 host protected by Windows Defender with real-time protection enabled. The tester wants to execute a custom .NET assembly in memory to avoid writing a payload to disk, but Defender's AMSI integration repeatedly flags the assembly when loaded via the standard reflection technique. Which modification to the in-memory loading approach is MOST likely to prevent AMSI from inspecting the assembly's content?

Medium
138

When testing for DOM-based XSS, where should you focus your analysis to find the vulnerable code?

Easy
139

A penetration tester delivers a custom .NET executable to a Windows 10 host running Microsoft Defender with cloud-delivered protection enabled. The binary contains an embedded shellcode blob in its .data section. After the loader decrypts the shellcode in memory and begins executing it, Defender terminates the process even though the file itself never touched disk again. Which technique would most directly address this specific detection?

Medium
140

A public exploit for a Linux service includes a compiled payload that connects back to a hardcoded IP address. You need to adapt it for your PEN-200 engagement. Which TWO actions are most appropriate? (Choose two.)

Hard
141

What role does the 'padding' play in a buffer overflow payload structure?

Medium
142

Refer to the exhibit. Based on the HTTP response headers provided, what critical information can be gathered for your reconnaissance?

Medium
143

You have successfully identified a Windows target and need to perform deep enumeration. Which TWO techniques are most effective for identifying hidden local services and internal network connections?

Medium
144

In the context of pivoting, what is 'double pivoting'?

Medium
145

An application is vulnerable to Server-Side Request Forgery (SSRF). You want to use this to scan the internal network. Which target should you attempt to access first to verify the vulnerability?

Hard
146

Refer to the exhibit. You are attempting a local port forward using PLINK, but receive a 'Connection refused' error. Which of the following is the most likely cause?

Hard
147

You have gained a foothold on an internal Linux host (10.10.10.20) that can reach a segregated network containing a web server at 192.168.100.50:80. Your attack machine cannot reach 192.168.100.50 directly. You want to use the compromised host to forward traffic from your machine's local port 8080 to 192.168.100.50:80. Which SSH command should you run from your attack machine?

Medium
148

Which of the following conditions is required to execute a successful Pass-the-Hash (PtH) attack against a target workstation?

Easy
149

An analyst is attempting to execute a custom C2 stager on a Windows 10 workstation with active Windows Defender. They decide to use a PowerShell one-liner that downloads a script from a remote server and executes it directly using the Invoke-Expression (IEX) cmdlet. Why is this method generally more effective than downloading an .exe file to the Desktop?

Medium
150

You have a low-privileged shell on a Windows Server 2016 host and run `whoami /priv`. The output shows `SeImpersonatePrivilege` enabled. You also notice that the `Print Spooler` service is running. Which technique would most directly allow you to escalate to NT AUTHORITY\SYSTEM?

Medium
151

Refer to the exhibit. Given the sudo privileges, which command will successfully spawn a root shell?

Easy
152

During a PEN-200 lab engagement, you obtain a low-privileged shell on a Windows machine and discover an unquoted service path containing spaces in its directory name. The service runs as Local System, but the parent folder has overly permissive discretionary access control lists granting standard users Full Control. How should you exploit this misconfiguration to escalate your privileges?

Medium
153

A penetration tester needs to deliver a Meterpreter payload to a Windows target protected by an EDR that performs both static file scanning and behavioral monitoring of process creation. The tester wants to reduce the chance of detection during initial execution while still obtaining a session. Which two techniques most directly reduce detection in this combined scenario? (Choose two.)

Hard
154

You find that a binary relies on a relative path to execute a secondary script. If you cannot modify the PATH variable, what is the best alternative to exploit this configuration?

Medium
155

Refer to the exhibit. What can you conclude about the security of this service binary?

Medium
156

Why is it important to use a local listener that matches the protocol expected by your exploit's payload?

Medium
157

You are testing a web application that uses a MySQL database. You suspect a UNION-based SQL injection in the 'id' parameter of a product page. The page displays product names and descriptions. Which two steps are necessary to successfully extract data using a UNION attack? (Choose two.)

Hard
158

Refer to the exhibit. [!] Error compiling payload: Function 'VirtualAlloc' not found in target assembly scope. An operator is writing a custom process injection loader in C# and encounters the compilation error shown above while attempting to allocate memory for shellcode. How should the operator properly resolve this issue to enable low-level memory allocation?

Medium
159

You are reviewing a public exploit for a Linux-based web application. The exploit is a Python script that uses a hardcoded offset to overwrite a return address, and it includes a comment stating it was tested on a specific kernel version. Your target runs a different kernel but the same application version. After running the exploit, the service crashes but no shell is obtained. Which action is the MOST appropriate next step?

Hard
160

Which TWO techniques are primarily used to bypass static signature-based detection by altering the file's binary appearance without changing its underlying functionality?

Medium
161

You are conducting a password spraying attack against an Active Directory environment. You have a list of common passwords and a list of usernames. To avoid locking out accounts, which approach should you take?

Medium
162

You have a low-privileged shell on a Linux host. You discover a cron job that runs every minute as root and executes a script located at /opt/backup/backup.sh. The script is world-writable. However, you also notice that the directory /opt/backup is owned by root and has permissions 755. Which of the following is the MOST reliable way to escalate privileges?

Hard
163

Refer to the exhibit. ```http HTTP/1.1 200 OK Server: nginx Content-Type: text/html; charset=UTF-8 Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' <html> <body> <h1>Welcome</h1> <script>var token = '12345';</script> </body> </html> ``` Based on the HTTP response headers and body shown in the exhibit, what significant security risk is present regarding client-side attacks?

Hard
164

During a penetration test, you have gained access to a workstation and extracted a Kerberos TGT for a domain user. You want to use this ticket to access a file share on another server without knowing the user's password. Which technique should you employ?

Hard
165

You are exploiting a 32-bit Windows FTP server that uses a fixed-size stack buffer and a vulnerable call to strcpy. After overwriting EIP with a JMP ESP address, you notice that your shellcode executes but the connection drops immediately without a shell. You suspect bad characters corrupted the payload. Which method is most effective for identifying all bad characters in this scenario?

Medium
166

You are performing a client-side phishing engagement and need to deliver a malicious payload using an ISO image file. Why is this delivery method often effective against modern Windows security warnings?

Medium
167

When evaluating antivirus evasion techniques for Windows targets in a penetration test, which TWO of the following approaches specifically target memory-based detection mechanisms rather than static disk signatures? (Choose TWO)

Hard
168

You are developing an exploit for a Windows 32-bit application with a stack buffer overflow. You have identified a JMP ESP instruction at a static address. However, the application uses SafeSEH. Which statement is true regarding the use of JMP ESP in this scenario?

Medium
169

During a stack-based buffer overflow exploit development exercise against a custom Windows application, an OSCP student successfully overwrites the instruction pointer (EIP) with the address of a JMP ESP instruction. However, upon triggering the vulnerability, the application immediately crashes with an access violation before executing the shellcode located directly after the return address. Which of the following is the most likely root cause of this execution failure?

Medium
170

You are conducting a penetration test and need to identify the operating system of a target host without sending any packets to it. Which of the following methods is most appropriate?

Easy
171

During exploitation of a stack-based buffer overflow on a 32-bit Windows application, you overwrite EIP with the address of a JMP ESP instruction, but the shellcode does not execute. You verify the JMP ESP address is correct and that the shellcode is in memory. Which of the following is the most likely cause?

Hard
172

You are using Proxychains to route your Nmap scan through a SOCKS proxy. Which configuration file must you modify to ensure that the proxy settings are correctly applied during your scan?

Easy
173

While testing a web application, you find that the login form is vulnerable to SQL injection. You input the username 'admin'-- and a blank password. The application logs you in as admin without validating the password. Which type of SQL injection attack is this?

Easy
174

You have compromised a domain user account and want to escalate privileges by abusing a misconfigured Group Policy Object (GPO). You discover that the GPO is linked to an Organizational Unit (OU) containing privileged servers and that the domain user has write permissions on the GPO. Which action should you take to escalate privileges?

Medium
175

During a penetration test, you want to exploit a client-side vulnerability by sending a link that will execute JavaScript in a victim’s browser when clicked. The target application uses a session cookie without the SameSite attribute. Which attack is most directly enabled by the missing SameSite attribute?

Medium
176

You have found a Python exploit that uses the 'requests' library but your target machine only has standard Python installed. What is your best course of action?

Medium
177

Which TWO of the following are common reasons for a buffer overflow exploit to fail even after the return address is correctly overwritten?

Medium
178

Which resource is most reliable for verifying that a public exploit is legitimate and does not contain hidden backdoors?

Easy
179

You have obtained a Windows domain user's NTLM hash and want to authenticate to a remote SMB service without cracking the hash or knowing the plaintext. Which tool and technique should you use to perform pass-the-hash against the target?

Medium
180

During an internal penetration test, you run a UDP scan against a Linux server and see the following result: `161/udp open snmp`. You want to extract as much host information as possible without triggering authentication failures. Which command should you run first?

Medium
181

During a PEN-200 lab engagement you locate a public exploit for a web application running on the target. The exploit's banner string is 'Mozilla/5.0' and the script appends the payload to a URL parameter. Before running it against the target, which action best reduces the risk of unintended side effects on the production web service?

Medium
182

During a network assessment, you want to enumerate users on a domain controller. Which protocol and port combination is the most standard target for this type of enumeration?

Medium
183

You have obtained a low-privileged shell on a Linux server. During enumeration, you discover a file named `backup.sh` in `/opt/scripts` that is owned by root and has permissions `-rwxr-xr-x`. A cron job runs this script every night as root. The directory `/opt/scripts` has permissions `drwxrwxr-x` and is owned by root:developers. Your user is a member of the `developers` group. What is the most reliable way to escalate privileges?

Hard
184

You have identified an AlwaysOn service running with SYSTEM privileges. The service binary is read-only, but you have write access to its directory. What is the most likely escalation vector?

Hard
185

During an assessment, you identify a Cross-Site Scripting vulnerability that allows you to execute arbitrary JavaScript in the context of a victim user's browser session. What is the primary objective of leveraging this capability against an authenticated user?

Easy
186

Which TWO of the following actions are considered best practice during the initial host enumeration phase to avoid detection by security monitoring tools?

Medium
187

You are performing a penetration test on a web application that uses a PHP session cookie. You notice the cookie lacks the HttpOnly flag. An attacker could exploit this by injecting a script that steals the cookie. Which attack technique is most directly enabled by the missing HttpOnly flag?

Medium
188

You have compromised a Windows server and want to escalate privileges using the `AlwaysInstallElevated` setting. You check the registry and find that both `HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` and `HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` are set to 1. What is the most direct way to leverage this misconfiguration?

Hard
189

During an authorized internal penetration test, you discover that the corporate proxy does not perform SSL inspection and allows outbound HTTPS to any destination. You need to deliver a client-side payload over HTTPS while evading signature-based network detection. Which technique is most appropriate?

Medium
190

When enumerating a web application, which THREE of the following items are most important to identify to increase the likelihood of finding a vulnerability?

Hard
191

You are analyzing a Windows 32-bit application that uses a fixed-size stack buffer and calls strcpy() without bounds checking. You want to determine the exact offset to overwrite the saved return address. Which tool or method is most appropriate for this task?

Easy
192

During a buffer overflow exploit development, you need to ensure that your shellcode does not contain any null bytes. You have generated shellcode that includes a null byte. Which of the following is the most appropriate action?

Medium
193

You are on a Windows 10 machine and discover that the folder 'C:\Temp' has permissions: BUILTIN\Users:(F). You also notice that a scheduled task runs every hour, executing 'C:\Temp\cleanup.exe' as SYSTEM. However, cleanup.exe does not exist in the folder. What is the most effective way to escalate privileges?

Medium
194

Which command is most useful for identifying processes that are running as root, which might be potential targets for privilege escalation?

Medium
195

Refer to the exhibit. You identify an Apache 2.4.49 vulnerability and locate the exploit. After reviewing the exploit code, you realize it requires a specific input format to trigger the path traversal. What is the most effective way to verify the vulnerability without crashing the server?

Hard
196

You have obtained a low-privileged domain user account and are performing internal enumeration. You identify a computer object in the domain where the 'ms-MCS-AdmPwd' attribute is readable by your user account. Which attack path does this vulnerability facilitate?

Medium
197

Why does enabling 'SMB Signing' prevent NTLM relay attacks?

Hard
198

During an internal assessment you compromise a workstation and recover a Kerberos TGS ticket from memory that belongs to a service account. Analysis shows the ticket was encrypted with the RC4-HMAC cipher using a key derived from the service account's password hash. You want to recover the plaintext password of that service account offline. Which action should you take?

Medium
199

Refer to the exhibit. What is the primary purpose of the command provided?

Medium
200

An attacker places a malicious 'version.dll' file into the same directory as a legitimate, signed executable that is known to load that DLL. When the legitimate program starts, it loads the malicious DLL instead of the one in the System32 folder. What evasion technique is being demonstrated?

Medium
201

Which THREE techniques are commonly implemented in malware to detect and evade dynamic analysis within an automated sandbox environment?

Hard
202

During an internal assessment, you compromise a workstation and recover a cached domain credential hash for a user who previously logged on. You want to use this hash to authenticate to a file server on the same network, but you do not know the plaintext password. Which of the following tools is specifically designed to perform Pass-the-Hash authentication from a Linux-based attack platform?

Medium
203

Refer to the exhibit. Which ports are currently open on the target host 192.168.1.10?

Easy
204

A penetration tester is preparing a Windows payload for a client engagement where the target endpoint runs a traditional signature-based antivirus product that does not perform cloud lookups. The tester wants to reduce the chance that the raw output of msfvenom is flagged during initial delivery. Which action best addresses this goal?

Easy
205

A penetration tester uses process hollowing to hide their payload inside 'svchost.exe'. They start the process in a suspended state, unmap its memory, write their shellcode, and resume the thread. What is a specific indicator that an advanced EDR might use to detect this activity?

Hard
206

You are auditing a web application and notice it uses base64 encoding to store user credentials in a cookie. What is the most accurate assessment of this security practice?

Easy
207

During an internal penetration test, you capture NTLMv2 challenge-response pairs from the network using Responder. The client is a Windows 10 workstation and the server is a Windows Server 2019 domain controller. You need to crack these NTLMv2 hashes offline. Which tool and mode correctly performs this attack?

Hard
208

Which of the following describes a successful Path Traversal attack in a web application?

Easy
209

While mapping a subnet you want to discover live hosts quickly before running detailed service scans. Which approach best fits an initial host-discovery sweep?

Easy
210

You have identified a vulnerable service using an outdated version of a CMS. You successfully locate a public exploit script on GitHub. What is the most critical first step before running this script against your target?

Medium
211

During external reconnaissance you collect DNS records for a target organization and find an MX record pointing to mail.example.com. You want to identify the IP addresses of other hosts in the same mail infrastructure without sending any packets directly to the target's servers. Which action best fits this passive goal?

Easy
212

You are assessing a web application that uses a strict Content Security Policy (CSP) with nonce-based script-src. You discover a reflected XSS vulnerability where your input is inserted into an existing <script> block that already has a valid nonce. Which action would most likely allow your JavaScript to execute despite the CSP?

Hard
213

During an authorized penetration test of a PHP e-commerce site, you discover that the 'remember me' cookie is created with the following code: setcookie('auth', base64_encode($user_id . ':' . $role), time()+2592000); The cookie value is 'MTIzNDp1c2Vy'. You decode it to '123:user'. The application trusts this cookie for authentication on subsequent requests. What is the MOST direct way to escalate privileges to administrator?

Medium
214

During an internal penetration test, you capture a NetNTLMv2 challenge-response hash from a Windows host. You want to crack it offline to recover the plaintext password. Which tool and mode should you use to maximize efficiency against this hash type?

Hard
215

When exploiting a service via 'Modify' permissions on its binary, why is it necessary to restart the service?

Medium
216

During an internal assessment you run a TCP SYN scan and note that a host responds with an RST/ACK for every probed port. What does this behavior most reliably indicate about the target host?

Medium
217

Which of the following is the most effective way to prevent Cross-Site Scripting (XSS) in a web application?

Medium
218

What is the most likely security risk associated with the configuration shown in the exhibit?

Medium
219

You have a low-privileged shell on a Windows 10 machine. While enumerating, you find that the folder C:\Program Files\CustomApp is writable by the Everyone group. Inside, there is an executable named updater.exe that is run as a service with SYSTEM privileges. However, the service is currently stopped. You want to escalate privileges by replacing updater.exe with a malicious binary. What is the most reliable way to ensure your malicious binary is executed with SYSTEM privileges?

Medium
220

When performing a DCSync attack, what is the core mechanism being exploited?

Medium
221

What is the primary purpose of an exploit payload in a buffer overflow context?

Easy
222

You are adapting a public exploit whose payload is a reverse shell. The exploit runs and the service reports success, but your netcat listener never receives a connection. Which cause is most likely?

Hard
223

You are performing a password spraying attack against an Active Directory environment. To avoid locking out accounts, which TWO of the following practices should you follow? (Choose two.)

Medium
224

During an engagement, you capture an AS-REP response from the domain controller. What is the specific prerequisite for this account to be vulnerable to AS-REP Roasting?

Medium
225

During an external penetration test, you discover a web application that uses a JSON Web Token (JWT) for authentication. The token header is {"alg":"HS256","typ":"JWT"}, and you have captured a valid token. You want to escalate privileges by modifying the "role" claim from "user" to "admin". Which action would most likely allow you to forge a valid token?

Medium
226

You are exploiting a 32-bit Windows application that reads a line of input into a 256-byte stack buffer using a vulnerable function. After sending a payload of 300 'A' characters, the application crashes and the debugger shows EIP contains 0x41414141. You need to determine the exact number of bytes from the start of the buffer to the saved return address. Which approach is most appropriate?

Medium
227

You have compromised a Linux jump host and need to access an internal web application on 192.168.1.50:80 that is firewalled from your local machine. You have SSH access to the jump host. Which command should you execute on your local machine to securely access the application via your browser?

Medium
228

When fuzzing an application to identify a buffer overflow, what is the most common symptom indicating that the application's memory boundaries have been exceeded?

Easy
229

A tester is preparing a reverse shell executable for a Windows target protected by a signature-based antivirus product. To reduce the chance the file is flagged, the tester wants to modify the binary so it no longer matches known signatures while keeping its behavior. Which action best accomplishes this?

Easy
230

During a Linux privilege escalation assessment, you discover that the current user can run `/usr/bin/find` via sudo without a password. You execute `sudo find /home -exec /bin/bash \;`. What is the outcome?

Medium
231

Which of the following describes the 'Open Redirect' vulnerability often used in phishing attacks?

Hard
232

You are analyzing a binary and identify a function that uses strcpy() to copy user input into a fixed-size stack buffer. Which register must be controlled to redirect the instruction pointer to your shellcode?

Medium
233

Refer to the exhibit. You are running a public exploit, but it fails with a 'Connection refused' error. What should you investigate first?

Hard
234

You are assessing a Windows host and discover the Print Spooler service is running. You locate a public PoC for CVE-2021-1675 that requires an attacker-controlled SMB share hosting a malicious DLL. You want to execute the exploit from your Kali machine against the target. Which action must you take FIRST before running the PoC?

Medium
235

You have compromised a Linux host that sits on both your external network and an isolated internal network containing a Windows server with SMB exposed. From your Kali machine you need to interact with the SMB service as if it were local. Which single command creates the correct tunnel?

Medium
236

You have compromised a service account that has the SeEnableDelegationPrivilege right on a domain controller. You want to abuse Kerberos delegation to gain access to a target server's file share. Which two steps are required to configure and exploit unconstrained delegation on a controlled computer object? (Choose two.)

Hard
237

You have obtained a plaintext password for a domain user and want to quickly identify which domain-joined systems the account can access with local administrative rights, without triggering account lockout. Which approach is most appropriate?

Easy
238

Why are static memory addresses for 'JMP ESP' preferred over dynamic stack addresses?

Medium
239

Refer to the exhibit. An analyst observes this response header after a successful login. What is the security implication of the 'HttpOnly' and 'Secure' flags set on the 'session_id' cookie?

Medium
240

During a penetration test, you discover that a web application uses an outdated version of a JavaScript library that contains a known DOM-based XSS vulnerability. The vulnerability is triggered when a specific URL parameter is processed by the library. Which action would best allow you to demonstrate the impact of this vulnerability to the client?

Easy
241

During a PEN-200 lab, a penetration tester develops a custom C# loader that allocates memory, writes shellcode, and executes it. Windows Defender's AMSI flags the process when the shellcode buffer is passed to a scanning routine. The tester wants to prevent AMSI from inspecting the buffer at runtime without disabling Defender. Which technique should the tester apply?

Medium
242

An attacker gains a low-privilege shell on a Windows 10 machine and discovers a third-party service named 'DataSync'. The attacker notes that the service runs as SYSTEM and they have 'FILE_WRITE_DATA' permissions on the service executable 'C:\Program Files\DataSync\sync.exe'. Which action is the most direct method to escalate privileges to SYSTEM?

Medium
243

Which command-line tool is primarily used during the reconnaissance phase to identify open ports and service versions on a remote target?

Easy
244

A penetration tester has a working PowerShell-based stager that is being blocked by AMSI on a Windows 11 target. The tester wants to keep using PowerShell for convenience but needs the stager to run without AMSI inspecting the script content. Which technique most directly targets AMSI's inspection of the script?

Medium
245

You identify a cron job running as root that executes a script located in a writable directory. What is the most reliable way to escalate privileges in this scenario?

Easy
246

When reviewing 'sudo -l' output, what does the 'NOPASSWD' tag signify for the listed command?

Easy
247

During a penetration test, you need to enumerate DNS records for the domain `example.com` to find subdomains and mail servers. Which command should you use to perform a zone transfer attempt?

Easy
248

You are performing a network scan on a target network and notice that ICMP echo requests are blocked, but you need to determine if the target host is alive. Which technique should you utilize to identify active hosts without relying on standard ICMP ping?

Medium
249

Why might a public exploit for a specific service fail to execute even when the service version matches the vulnerability description exactly?

Medium
250

During an authorized penetration test, you deliver a malicious script to a victim's browser by exploiting a reflected XSS vulnerability. The script executes in the context of the vulnerable application and silently sends a crafted HTTP request to the application's password-change endpoint. The victim is currently authenticated. Which client-side attack technique are you performing?

Medium
251

A penetration tester has compromised a Linux host and wants to use it as a pivot to reach an internal network. The tester decides to use SSH local port forwarding to access an internal web server at 10.0.0.5:80 from their attacking machine. Which command should the tester run on the attacking machine?

Easy
252

During an internal assessment, you find a public exploit for a Jenkins script console vulnerability. The exploit sends a Groovy script to /script via a POST request. When you run it, the server returns HTTP 403. The Jenkins version matches the vulnerable range, and the endpoint is reachable. Which is the MOST likely reason the exploit fails?

Hard
253

You have identified an open port 445 on a Windows machine. Which tool is most effective for checking if the machine is vulnerable to common SMB-based exploits like EternalBlue?

Medium
254

You need to fingerprint the web server technology behind an HTTP service without sending malformed or intrusive requests. Which two actions best accomplish passive-leaning banner and behavior fingerprinting during enumeration? (Choose two.)

Medium
255

You are attempting to escalate privileges on a Windows target and decide to exploit unquoted service paths. You find a service with the binary path `C:\Program Files\My App\service.exe` and the service is running as LocalSystem. Which condition must be true for this unquoted path to be exploitable?

Medium
256

During a PEN-200 lab exercise, you find a public exploit for a Windows service. The exploit source contains a hardcoded return address of 0x41414141 and a comment that it was tested against a different Windows build with ASLR disabled. What should you do before running it against your target?

Medium
257

You have a Windows host with outbound internet access but want to avoid installing a full agent. You decide to use Chisel to pivot. Which statement accurately describes how Chisel establishes the tunnel in this scenario?

Easy
258

During an exploit development exercise on a 32-bit Windows application, you have identified that a JMP ESP instruction resides at 0x625011AF inside a module that is not protected by ASLR or SafeSEH. You need to place your shellcode after the overwritten return address. What is the primary reason for using this JMP ESP address rather than jumping directly to a stack address where your shellcode resides?

Medium
259

During an authorized penetration test, a tester needs to deliver a Meterpreter payload to a Windows Server 2019 target that runs a next-generation antivirus with behavioral monitoring. The tester decides to use a process injection technique to run the payload inside a legitimate process. Which injection method is LEAST likely to be flagged by behavioral monitoring because it avoids allocating new executable memory in the target process?

Hard
260

Why must you carefully identify 'bad characters' before finalizing an exploit payload?

Hard
261

You are performing a penetration test against a Linux server and have obtained a copy of the /etc/shadow file. The file contains a hash for user 'admin' that starts with '$6$'. You want to crack this hash offline. Which hashcat mode should you use?

Easy
262

A web application uses JSON Web Tokens for authentication. You capture a token whose header is `{"alg":"HS256","typ":"JWT"}` and payload is `{"user":"guest","role":"user"}`. The server verifies the signature with a symmetric secret. Which attack is most likely to let you forge a token with `"role":"admin"` if the application is misconfigured?

Easy
263

You are testing an e-commerce application that uses a cookie named 'sessionid' to maintain authenticated sessions. The application sets this cookie without the HttpOnly attribute, and you have identified a reflected XSS vulnerability in the product search feature. Which of the following attack methods would allow you to steal the session cookie and hijack an authenticated user's session?

Hard
264

You are testing a web application that sets a session cookie with the HttpOnly flag. You find a reflected XSS vulnerability on a page that does not require authentication. What is the primary impact of exploiting this XSS given the HttpOnly flag?

Hard
265

Which of the following best describes the function of the EIP register in the context of a stack-based buffer overflow?

Easy
266

Refer to the exhibit. If you attempt an SSH remote port forward (-R) to bind a port to all network interfaces on the server, what will happen?

Hard
267

A penetration tester has a working unmanaged PowerShell runner in C# that executes a script block on a Windows 10 host with AMSI enabled. The runner currently fails because AMSI scans the script content. The tester wants to disable AMSI scanning for the current process without touching files on disk and without requiring administrative privileges. Which technique best fits these constraints?

Hard
268

When analyzing a public exploit, which TWO elements should you specifically look for to understand its networking behavior? (Choose TWO)

Medium
269

You are fuzzing a Linux x86-64 network service and cause a segmentation fault. You run the binary under GDB and see that the instruction pointer is 0x41414141. However, the crash address is in a non-executable stack region. Which technique should you use to redirect execution to your shellcode?

Medium
270

You have compromised a dual-homed Linux host that can reach an internal network. You want to use it as a SOCKS proxy so that tools like Nmap and Metasploit can route traffic into that internal network. You decide to use SSH dynamic port forwarding. Which command should you run from your attacking machine to create a SOCKS proxy on local port 1080 that tunnels through the compromised host?

Hard
271

You download a public exploit for a known vulnerability from an untrusted source. Before running it against a client's production system, what is the most important action to take?

Easy
272

You are enumerating an Apache web server and discover the '.git' directory is accessible. What is the most significant risk this poses for your reconnaissance?

Medium
273

During an Active Directory penetration test, you have obtained Domain Admin privileges. To maintain persistent access, you decide to create a Golden Ticket. Which two of the following pieces of information are required to forge a valid Golden Ticket? (Choose two.)

Hard
274

When analyzing a stack buffer, what is the significance of the 'saved EBP' value?

Easy
275

You are enumerating a Windows host and have obtained valid low-privilege domain credentials. You want to identify which systems in the domain the account can access administratively, so you can plan lateral movement. Which approach most efficiently maps that access?

Hard
276

When evaluating a web application for Cross-Site Scripting vulnerabilities during a penetration test, which TWO input contexts should you examine because they frequently lead to executable script injection?

Hard
277

You are assessing a login form and suspect a blind SQL injection vulnerability. The application does not return database errors, but the response time varies significantly based on the input. Which TWO of the following techniques would be most effective to confirm this vulnerability?

Medium
278

During enumeration, you discover that the registry keys 'HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' and 'HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' are both set to 1. Which of the following is the most efficient way to exploit this configuration?

Medium
279

During an internal penetration test, you gain shell access to a Linux machine. You want to pivot deeper into a segmented internal network that is completely unreachable directly from your attack host. Which tunneling approach establishes a true layer 2 network tunnel by creating a virtual network interface, allowing you to route raw Ethernet frames and perform ARP scanning?

Medium
280

Which property of a URL is most commonly used as a source for DOM-based XSS because it is not sent to the server?

Medium
281

A penetration tester is preparing to bypass antivirus on a Windows target during a PEN-200 lab. The tester wants to use packing and encryption to alter the payload's signature and avoid static detection. Which TWO techniques are effective for evading static signature-based detection by changing the file's binary appearance without altering its functionality? (Choose two.)

Medium
282

You have gained a low-privileged shell on a Linux system and discovered a binary with the SUID bit set. The binary executes a system call to 'cat' without specifying an absolute path. How can you leverage this to escalate privileges?

Medium
283

Refer to the exhibit. What is the most likely goal of this command execution in a privilege escalation context?

Medium
284

What is the primary objective of a 'Clickjacking' attack?

Easy
285

During a web assessment, you find that an application uses an insecure random number generator for token creation. What is the main security implication of this flaw?

Medium

Frequently asked questions

What does the scenario questions domain cover on the PEN-200 exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 285 scenario questions questions in the PEN-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.