Courseiva
Client-Side Attacks →easyMultiple Choice

PEN-200 Client-Side Attacks Practice Question

During a client-side assessment, you find that an application accepts a user-supplied URL parameter and later uses it to redirect the browser away from the site without validating the destination. Which vulnerability class does this behavior represent, and what is its most direct client-side impact?

⚠ Common exam trap

The trap here is assuming any client-side URL handling must be XSS, when an unvalidated redirect produces navigation rather than script execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Open redirect, because the browser can be sent to an attacker-controlled destination for phishing or credential harvesting

An unvalidated redirect parameter turns the trusted application into an open redirect. Because the link points at the legitimate domain, victims are more likely to trust it, and the attacker can land them on a credential-harvesting page or malicious download. The key impact is phishing facilitation, not script execution or request forgery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Open redirect, because the browser can be sent to an attacker-controlled destination for phishing or credential harvesting

    Why this is correct

    When a parameter controls a navigation target without validation, the site becomes an open redirect. Attackers abuse the trusted domain to send victims to a lookalike login page or malware host, which is especially convincing in phishing. This matches the described behavior and its most direct client-side consequence.

  • ✗

    CSRF, because the redirect causes the victim to submit a forged request

    Why it's wrong here

    CSRF involves a forged state-changing request sent with the victim's ambient credentials, typically from a third-party page. An unvalidated redirect merely changes where the browser goes; it does not construct an authenticated request on the user's behalf. The two issues are distinct and this description does not fit the scenario.

  • ✗

    Clickjacking, because the redirect overlays a transparent frame on the page

    Why it's wrong here

    Clickjacking relies on framing the target site and tricking the user into clicking concealed elements. An unvalidated redirect does not involve framing or UI redressing at all. It changes the navigation destination, so labeling it clickjacking misidentifies both the mechanism and the impact.

  • ✗

    DOM-based XSS, because the redirect executes script in the victim's browser

    Why it's wrong here

    DOM-based XSS requires script execution from a client-side sink such as innerHTML or eval. A plain unvalidated redirect navigates the browser to another location but does not itself execute attacker JavaScript in the origin. It therefore mischaracterizes the finding and overstates its immediate impact.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.