Courseiva
Client-Side Attacks →easyMultiple Choice

PEN-200 Client-Side Attacks Practice Question

During an assessment, you identify a Cross-Site Scripting vulnerability that allows you to execute arbitrary JavaScript in the context of a victim user's browser session. What is the primary objective of leveraging this capability against an authenticated user?

⚠ Common exam trap

Students often believe XSS is solely useful for defacing web pages or executing simple alerts, failing to recognize its power in stealing session tokens for unauthorized access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hijacking the user session by accessing session tokens or performing actions on their behalf within the application

XSS allows attackers to execute scripts in the victim browser session, giving them access to document.cookie, local storage, and the ability to perform actions on behalf of the user. This effectively hijacks their session without needing to crack their underlying password.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Extracting plaintext password hashes directly from the remote web server operating system memory

    Why it's wrong here

    Browser JavaScript cannot read remote server process memory, so operating system credential extraction is unreachable from this context. XSS is leveraged to act within the victim's authenticated session, for example issuing same-origin requests or exfiltrating tokens, not to dump host memory.

  • ✓

    Hijacking the user session by accessing session tokens or performing actions on their behalf within the application

    Why this is correct

    Executing JavaScript in the victim browser permits access to session identifiers stored in cookies or local storage, facilitating session hijacking. The attacker can also forge HTTP requests using the user's active session to perform unauthorized administrative actions.

  • ✗

    Modifying the enterprise DNS records hosted on the primary domain controller via client-side DOM manipulation

    Why it's wrong here

    JavaScript runs in the browser sandbox and cannot reach the domain controller or modify DNS zone data; DOM manipulation affects only the rendered page. Client-side script is used to read the victim's session, cookies or CSRF tokens, not to alter server-side directory records.

  • ✗

    Bypassing enterprise firewall packet inspection rules by encapsulating shellcode inside HTTPS headers

    Why it's wrong here

    XSS executes JavaScript in the victim's browser session, enabling session hijacking, credential theft or CSRF-style actions; it cannot tunnel shellcode through HTTPS headers, which is a network-layer evasion technique. Encapsulating payloads in HTTPS headers is tempting for bypassing deep packet inspection, but that belongs to command-and-control or exfiltration scenarios, not browser-based script execution.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.