Courseiva
Client-Side Attacks →easyMultiple Choice

PEN-200 Client-Side Attacks Practice Question

During a penetration test, you discover that a web application uses an outdated version of a JavaScript library that contains a known DOM-based XSS vulnerability. The vulnerability is triggered when a specific URL parameter is processed by the library. Which action would best allow you to demonstrate the impact of this vulnerability to the client?

⚠ Common exam trap

The trap here is overcomplicating the exploitation by using proxies or SQL injection, when the DOM-based XSS can be triggered simply by delivering a crafted URL to a victim.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Craft a URL with a malicious payload in the vulnerable parameter and send it to a victim user.

The best action is to craft a URL with a malicious payload in the vulnerable parameter and send it to a victim. Because the vulnerability is DOM-based and triggered by URL parameters, visiting the link executes the payload in the victim's browser. This directly demonstrates the impact, such as session hijacking or data theft, and is a standard proof of concept for DOM-based XSS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform a brute-force attack to guess the victim's credentials and log in as them.

    Why it's wrong here

    Brute-forcing credentials is a different attack vector and does not demonstrate the DOM-based XSS vulnerability. It would not show how the library flaw can be exploited to execute script in a victim's browser. The client needs to understand the client-side risk, so a URL-based payload is more appropriate. Brute-forcing is ineffective and unrelated.

  • ✗

    Use a web proxy to intercept and modify the library's JavaScript file to include a malicious payload.

    Why it's wrong here

    Modifying the library file via a proxy would only affect your own browsing session, not other users. It does not demonstrate a vulnerability that can be exploited against victims. The vulnerability is already present in the outdated library, so there is no need to modify it. This approach would not prove the impact to the client.

  • ✓

    Craft a URL with a malicious payload in the vulnerable parameter and send it to a victim user.

    Why this is correct

    Since the vulnerability is DOM-based and triggered by a URL parameter, crafting a URL with a malicious payload and delivering it to a victim will execute the script in the victim's browser when they visit the link. This demonstrates the impact by showing how an attacker could steal data or perform actions. It is a direct proof of concept for reflected DOM-based XSS.

  • ✗

    Exploit a SQL injection vulnerability to extract the library's source code and identify the flaw.

    Why it's wrong here

    SQL injection is a server-side vulnerability and unrelated to DOM-based XSS. Extracting source code might help identify the flaw, but it does not demonstrate the client-side impact. The scenario already states the library has a known DOM-based XSS vulnerability; the goal is to show exploitability, not to find it. SQL injection is not the right tool here.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.