PEN-200 Client-Side Attacks Practice Question
During an authorized penetration test, you want to perform a client-side attack by delivering a malicious HTA file via a phishing email. Which technique is most effective to execute native commands silently when the user opens the file?
⚠ Common exam trap
Many candidates incorrectly assume that HTA files act like standard HTML files in a browser. They forget that HTA files are executed by mshta.exe, which operates outside the browser sandbox.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using mshta.exe to process a VBScript payload embedded within the HTA container to spawn a reverse shell
HTA files execute via mshta.exe, allowing VBScript or JScript integration to run operating system commands directly without standard browser security sandboxes. This makes HTA files highly effective for initial access vectors during social engineering engagements when users trust and run local executables.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Embedding the HTA inside a standard PDF document using an external URI scheme pointing to a remote script
Why it's wrong here
PDF files use different rendering engines and cannot natively execute HTA payloads directly inside their document structure. While PDFs can trigger external links or launch embedded binaries, mshta.exe execution requires direct file invocation or browser-based protocol handlers rather than standard PDF readers.
- ✗
Hosting the HTA file on an Apache web server with a fake mime-type configuration forcing automatic execution
Why it's wrong here
Modern web browsers enforce strict MIME-type checking and security policies that prevent automatic execution of downloaded binaries. Even if the server misconfigures the Content-Type header, the browser will either block the download or prompt the user, requiring manual local execution.
- ✓
Using mshta.exe to process a VBScript payload embedded within the HTA container to spawn a reverse shell
Why this is correct
The mshta.exe utility natively interprets HTML Applications and executes embedded scripting languages like VBScript or JScript with the full privileges of the current user. This bypasses typical browser isolation boundaries because the file runs as a trusted local Windows application.
- ✗
Converting the HTA payload into a malicious shortcut (.lnk) file that calls PowerShell with hidden window arguments
Why it's wrong here
Shortcut files rely on invoking cmd.exe or powershell.exe directly rather than utilizing the mshta binary format. While .lnk files are a common delivery vector, they do not leverage HTML Application mechanics or the specific script-processing capabilities of the mshta engine.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.