PEN-200 Client-Side Attacks Practice Question
During a client-side assessment, you find that an application accepts a user-supplied URL parameter and later uses it to redirect the browser away from the site without validating the destination. Which vulnerability class does this behavior represent, and what is its most direct client-side impact?
⚠ Common exam trap
The trap here is assuming any client-side URL handling must be XSS, when an unvalidated redirect produces navigation rather than script execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Open redirect, because the browser can be sent to an attacker-controlled destination for phishing or credential harvesting
An unvalidated redirect parameter turns the trusted application into an open redirect. Because the link points at the legitimate domain, victims are more likely to trust it, and the attacker can land them on a credential-harvesting page or malicious download. The key impact is phishing facilitation, not script execution or request forgery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Open redirect, because the browser can be sent to an attacker-controlled destination for phishing or credential harvesting
Why this is correct
When a parameter controls a navigation target without validation, the site becomes an open redirect. Attackers abuse the trusted domain to send victims to a lookalike login page or malware host, which is especially convincing in phishing. This matches the described behavior and its most direct client-side consequence.
- ✗
CSRF, because the redirect causes the victim to submit a forged request
Why it's wrong here
CSRF involves a forged state-changing request sent with the victim's ambient credentials, typically from a third-party page. An unvalidated redirect merely changes where the browser goes; it does not construct an authenticated request on the user's behalf. The two issues are distinct and this description does not fit the scenario.
- ✗
Clickjacking, because the redirect overlays a transparent frame on the page
Why it's wrong here
Clickjacking relies on framing the target site and tricking the user into clicking concealed elements. An unvalidated redirect does not involve framing or UI redressing at all. It changes the navigation destination, so labeling it clickjacking misidentifies both the mechanism and the impact.
- ✗
DOM-based XSS, because the redirect executes script in the victim's browser
Why it's wrong here
DOM-based XSS requires script execution from a client-side sink such as innerHTML or eval. A plain unvalidated redirect navigates the browser to another location but does not itself execute attacker JavaScript in the origin. It therefore mischaracterizes the finding and overstates its immediate impact.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.