PEN-200 · domain
Web Application Attacks
This domain covers attacking web applications on the PEN-200/OSCP path: directory and path traversal, file inclusion, command injection, SQL injection, XSS, and JWT flaws. You enumerate with Burp Suite and ffuf, then exploit manually or with sqlmap, and must produce working proof plus remediation reasoning.
Focused practice
Practice Web Application Attacks questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Web Application Attacks
You must manually confirm and exploit web flaws, then show impact with a captured flag or file. The most important thing is understanding input handling and filters so you can adapt payloads instead of relying on one tool's defaults.
Exploiting path traversal with encoded ../ sequences to read files outside the web root
Using Burp Suite Repeater and ffuf to fuzz parameters, directories, and file extensions
Command injection via shell metacharacters in parameters passed to system() or exec()
JWT attacks including alg:none and weak HS256 secret cracking with hashcat or john
Watch out for
Common Web Application Attacks exam traps
- ▸Assuming a single ../ works; forgetting URL encoding, double encoding, or absolute paths when filters strip traversal sequences
- ▸Testing only reflected XSS payloads and missing stored or DOM-based variants, or ignoring context-specific encoding needs
- ▸Blindly running sqlmap without confirming injection manually or identifying the DBMS, leading to wrong tamper and dump options
Question index
All Web Application Attacks questions (27)
Click any question to see the full explanation, or start a practice session above.
Which of the following is a common symptom of a Command Injection vulnerability?
Easy2You are assessing a web application that uses a relational database backend. During manual testing, you suspect a UNION-based SQL injection vulnerability in a product category parameter. Which two of the following steps are necessary to successfully extract data using a UNION-based SQL injection attack? (Choose two.)
Medium3You are testing a Java-based web application that uses the Spring framework. The application has an endpoint /api/users/{id} that returns user details in JSON. When you request /api/users/123, you receive your own details. You then request /api/users/124 and receive another user's details. The application uses a session cookie but does not implement any role-based checks on this endpoint. What is the MOST appropriate next step to demonstrate the impact of this vulnerability?
Hard4Which of the following describes a stored Cross-Site Scripting (XSS) attack?
Easy5During a penetration test against a web application, you identify a parameter vulnerable to Blind SQL Injection. The backend database is Microsoft SQL Server, and the application does not return any error messages or query results. Which technique should you use to exfiltrate data character by character based on application behavior?
Medium6During an authorized web application assessment, you discover a search page that reflects the query parameter directly into the HTML response body without encoding. You want to confirm the presence of a reflected cross-site scripting vulnerability using a minimal, non-destructive payload. Which of the following payloads is most likely to execute JavaScript in a victim's browser when injected into the vulnerable parameter?
Medium7While auditing a web application, you identify an endpoint that retrieves profile images via a URL parameter: 'image.php?file=profile.jpg'. Changing the parameter to 'image.php?file=/etc/passwd' returns the contents of the system password file. Which vulnerability is present, and what is the primary risk?
Medium8What is the primary security risk of an application that fails to properly validate the 'Content-Type' header during a file upload process?
Medium9You are testing a Java web application that stores user-supplied SVG avatars. The application sanitizes SVG files by stripping `<script>` tags, then serves them from the same origin with `Content-Type: image/svg+xml`. When a victim views another user's profile, the browser renders the SVG inline. Which technique most reliably achieves script execution in the victim's session despite the sanitizer?
Hard10What is the primary goal of utilizing an intercepting proxy during a web application penetration test?
Easy11During a web application assessment, you identify a blind SQL injection vulnerability in a cookie parameter. The backend database is PostgreSQL. You want to determine the first character of the database name using a time-based injection. Which of the following payloads would correctly test if the first character is 'p' by causing a 5-second delay?
Medium12Which of the following describes the security benefit of the 'HttpOnly' flag shown in the exhibit?
Medium13You are performing a penetration test against a web application that uses a Linux backend. You discover a file inclusion vulnerability in the 'page' parameter: 'index.php?page=home.php'. You attempt to include '/etc/passwd' using path traversal, but the application appends '.php' to the input. You try 'page=../../../../etc/passwd%00' but the null byte is blocked. Which of the following techniques is most likely to allow you to read the '/etc/passwd' file?
Hard14An application is vulnerable to Server-Side Request Forgery (SSRF). You want to use this to scan the internal network. Which target should you attempt to access first to verify the vulnerability?
Hard15You are testing a web application that uses a MySQL database. You suspect a UNION-based SQL injection in the 'id' parameter of a product page. The page displays product names and descriptions. Which two steps are necessary to successfully extract data using a UNION attack? (Choose two.)
Hard16While testing a web application, you find that the login form is vulnerable to SQL injection. You input the username 'admin'-- and a blank password. The application logs you in as admin without validating the password. Which type of SQL injection attack is this?
Easy17You are performing a penetration test on a web application that uses a PHP session cookie. You notice the cookie lacks the HttpOnly flag. An attacker could exploit this by injecting a script that steals the cookie. Which attack technique is most directly enabled by the missing HttpOnly flag?
Medium18Which of the following describes a successful Path Traversal attack in a web application?
Easy19During an authorized penetration test of a PHP e-commerce site, you discover that the 'remember me' cookie is created with the following code: setcookie('auth', base64_encode($user_id . ':' . $role), time()+2592000); The cookie value is 'MTIzNDp1c2Vy'. You decode it to '123:user'. The application trusts this cookie for authentication on subsequent requests. What is the MOST direct way to escalate privileges to administrator?
Medium20Which of the following is the most effective way to prevent Cross-Site Scripting (XSS) in a web application?
Medium21What is the most likely security risk associated with the configuration shown in the exhibit?
Medium22During an external penetration test, you discover a web application that uses a JSON Web Token (JWT) for authentication. The token header is {"alg":"HS256","typ":"JWT"}, and you have captured a valid token. You want to escalate privileges by modifying the "role" claim from "user" to "admin". Which action would most likely allow you to forge a valid token?
Medium23Refer to the exhibit. An analyst observes this response header after a successful login. What is the security implication of the 'HttpOnly' and 'Secure' flags set on the 'session_id' cookie?
Medium24A web application uses JSON Web Tokens for authentication. You capture a token whose header is `{"alg":"HS256","typ":"JWT"}` and payload is `{"user":"guest","role":"user"}`. The server verifies the signature with a symmetric secret. Which attack is most likely to let you forge a token with `"role":"admin"` if the application is misconfigured?
Easy25You are testing an e-commerce application that uses a cookie named 'sessionid' to maintain authenticated sessions. The application sets this cookie without the HttpOnly attribute, and you have identified a reflected XSS vulnerability in the product search feature. Which of the following attack methods would allow you to steal the session cookie and hijack an authenticated user's session?
Hard26You are assessing a login form and suspect a blind SQL injection vulnerability. The application does not return database errors, but the response time varies significantly based on the input. Which TWO of the following techniques would be most effective to confirm this vulnerability?
Medium27During a web assessment, you find that an application uses an insecure random number generator for token creation. What is the main security implication of this flaw?
MediumOther domains
All PEN-200 exam domains
Frequently asked questions
- What does the Web Application Attacks domain cover on the PEN-200 exam?
- You must manually confirm and exploit web flaws, then show impact with a captured flag or file. The most important thing is understanding input handling and filters so you can adapt payloads instead of relying on one tool's defaults.
- How many questions are in this domain?
- This page lists all 27 Web Application Attacks questions in the PEN-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Web Application Attacks questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.