PEN-200 Public Exploits Practice Question
During a PEN-200 lab engagement you locate a public exploit for a web application running on the target. The exploit's banner string is 'Mozilla/5.0' and the script appends the payload to a URL parameter. Before running it against the target, which action best reduces the risk of unintended side effects on the production web service?
⚠ Common exam trap
The trap here is assuming that a script's built-in safety flag or a dry-run URL substitution proves the exploit is harmless when neither actually exercises the vulnerable code path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the exploit's HTTP request construction and test it against a local instance of the same application version.
Examining how the exploit builds its HTTP request and replaying it against a matching local instance is the only approach that both reveals the payload's behavior and prevents production impact. Local reproduction lets the tester observe success or failure and confirm the exploit is appropriate before touching the live service, which is the safe validation workflow emphasized in PEN-200.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Review the exploit's HTTP request construction and test it against a local instance of the same application version.
Why this is correct
Auditing the request construction reveals exactly what parameters and payloads are sent, and reproducing the same application version locally lets you observe the exploit's real effect without touching the production service. This combination gives verifiable behavior before any live request, which is the core discipline of safe exploit validation in PEN-200.
- ✗
Increase the exploit's timeout value to ensure the request completes fully before you observe the result.
Why it's wrong here
Timeout tuning affects only how long the script waits for a response; it does not change what the exploit sends or whether it is destructive. A longer timeout may even allow a resource-heavy payload to run longer on the target, increasing the chance of service disruption instead of reducing risk as the scenario requires.
- ✗
Change the target URL to a non-existent host so the exploit exits early, then redirect it to the real target.
Why it's wrong here
Pointing the exploit at a non-existent host only tests network error handling; it never exercises the vulnerable code path or the payload. Once redirected to the real target, the exploit behaves exactly as it would have without the test, so no meaningful safety information is gained and the production service remains fully exposed to the payload.
- ✗
Run the exploit with a --safe flag if the script supports it, then immediately run it against the target.
Why it's wrong here
A --safe flag is not a standard feature of public exploit scripts and provides no verification that the payload will behave as intended on the live target. Relying on an undocumented flag leaves the actual request and payload unexamined, so the operator still cannot predict whether the exploit will alter data, spawn shells, or crash the service.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.