Courseiva
Client-Side Attacks →mediumMultiple Choice

PEN-200 Client-Side Attacks Practice Question

During an authorized penetration test, you discover that a web application’s password reset page reflects the `email` parameter inside a JavaScript string literal with no output encoding. You want to execute arbitrary JavaScript in a victim’s browser when they click a crafted password-reset link. Which payload should you use?

⚠ Common exam trap

The trap here is assuming any reflected input can be exploited with a generic HTML tag or attribute payload without first identifying the exact parsing context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

`";alert(document.domain)//`

The reflection occurs inside a JavaScript string literal, so the payload must first break out of that string using a matching quote, then execute code. The double-quote-based payload with a comment terminator achieves this while preserving the rest of the script’s syntax. HTML-oriented payloads fail because the parser is already inside a script data state, not an HTML tag or attribute context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    `";alert(document.domain)//`

    Why this is correct

    The email parameter is reflected inside a JavaScript string literal. Breaking out with a double quote, terminating the statement with a semicolon, and invoking alert() executes script in the page context. The trailing // comments out the remaining original script, avoiding syntax errors. This works because the reflection lacks JavaScript string escaping, not because of HTML context.

  • ✗

    `<script>alert(document.domain)</script>`

    Why it's wrong here

    The injection point is inside a JavaScript string, not in HTML body content. A script tag would be treated as literal text within the JavaScript string and would not create a new script element. HTML-parsing payloads fail because the browser has already entered the script data state before reaching the reflected value, so no tag is constructed.

  • ✗

    `' onmouseover='alert(document.domain)`

    Why it's wrong here

    This payload targets an HTML attribute context, attempting to close an attribute and add an event handler. Because the reflection is inside a JavaScript string, the single quote and onmouseover text remain inside the string and are never parsed as HTML attributes. No event is registered and no script executes in this scenario.

  • ✗

    `javascript:alert(document.domain)`

    Why it's wrong here

    The javascript: pseudo-protocol only executes when used as a URL in an href or similar navigation context. Here the value is embedded in a script string, so the browser treats it as plain characters, not a navigable URI. It cannot break out of the string or execute code in this reflection context.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.