PEN-200 Client-Side Attacks Practice Question
During an authorized internal penetration test, you discover that the corporate proxy does not perform SSL inspection and allows outbound HTTPS to any destination. You need to deliver a client-side payload over HTTPS while evading signature-based network detection. Which technique is most appropriate?
⚠ Common exam trap
The trap here is assuming that any HTTPS delivery automatically evades detection, when in fact certificate validity, domain reputation, and traffic categorization are what determine whether the connection blends in.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Serve the payload from a valid TLS certificate on a domain categorized as business-related, using domain fronting through a CDN.
Domain fronting through a CDN with a valid certificate and a business-categorized domain conceals the true destination in the TLS SNI, allowing the payload to be delivered over HTTPS while blending with legitimate traffic. This evades signature-based network detection that relies on domain or IP reputation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send the payload as a base64-encoded attachment in a plain SMTP email to the target user.
Why it's wrong here
Plain SMTP email is often scanned by email security gateways that decode base64 and inspect attachments. It does not provide end-to-end encryption or domain fronting, so the payload may be blocked or quarantined. This approach also lacks the HTTPS transport needed to evade signature-based network detection.
- ✓
Serve the payload from a valid TLS certificate on a domain categorized as business-related, using domain fronting through a CDN.
Why this is correct
Domain fronting leverages a CDN's shared TLS endpoint to hide the true destination in the encrypted SNI, so network defenders only see a benign domain. Combined with a valid TLS certificate and business categorization, it blends with normal traffic and bypasses signature-based detection that relies on IP or domain reputation.
- ✗
Host the payload on an unregistered domain with a self-signed certificate and rely on the user to click through the browser warning.
Why it's wrong here
A self-signed certificate triggers browser warnings that most users will not bypass, reducing success rates. Unregistered domains are often flagged by reputation services, and the lack of a valid certificate makes the traffic stand out. This method does not achieve the required evasion against signature-based detection.
- ✗
Embed the payload in an ICMP echo request and use a custom tunnel to the target workstation.
Why it's wrong here
ICMP tunneling requires the target to accept and process ICMP payloads, which is uncommon and often blocked by host firewalls. It also generates unusual traffic patterns that anomaly-based detection can flag. This method does not provide the HTTPS transport needed to blend with normal web traffic and is easily detected.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.