Courseiva
Client-Side Attacks →mediumMultiple Choice

PEN-200 Client-Side Attacks Practice Question

During an authorized penetration test, you want to perform a client-side attack by delivering a malicious HTA file via a phishing email. Which technique is most effective to execute native commands silently when the user opens the file?

⚠ Common exam trap

Many candidates incorrectly assume that HTA files act like standard HTML files in a browser. They forget that HTA files are executed by mshta.exe, which operates outside the browser sandbox.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using mshta.exe to process a VBScript payload embedded within the HTA container to spawn a reverse shell

HTA files execute via mshta.exe, allowing VBScript or JScript integration to run operating system commands directly without standard browser security sandboxes. This makes HTA files highly effective for initial access vectors during social engineering engagements when users trust and run local executables.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Embedding the HTA inside a standard PDF document using an external URI scheme pointing to a remote script

    Why it's wrong here

    PDF files use different rendering engines and cannot natively execute HTA payloads directly inside their document structure. While PDFs can trigger external links or launch embedded binaries, mshta.exe execution requires direct file invocation or browser-based protocol handlers rather than standard PDF readers.

  • ✗

    Hosting the HTA file on an Apache web server with a fake mime-type configuration forcing automatic execution

    Why it's wrong here

    Modern web browsers enforce strict MIME-type checking and security policies that prevent automatic execution of downloaded binaries. Even if the server misconfigures the Content-Type header, the browser will either block the download or prompt the user, requiring manual local execution.

  • ✓

    Using mshta.exe to process a VBScript payload embedded within the HTA container to spawn a reverse shell

    Why this is correct

    The mshta.exe utility natively interprets HTML Applications and executes embedded scripting languages like VBScript or JScript with the full privileges of the current user. This bypasses typical browser isolation boundaries because the file runs as a trusted local Windows application.

  • ✗

    Converting the HTA payload into a malicious shortcut (.lnk) file that calls PowerShell with hidden window arguments

    Why it's wrong here

    Shortcut files rely on invoking cmd.exe or powershell.exe directly rather than utilizing the mshta binary format. While .lnk files are a common delivery vector, they do not leverage HTML Application mechanics or the specific script-processing capabilities of the mshta engine.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.