Courseiva
Web Application Attacks →mediumMultiple Choice

PEN-200 Web Application Attacks Practice Question

During an authorized web application assessment, you discover a search page that reflects the query parameter directly into the HTML response body without encoding. You want to confirm the presence of a reflected cross-site scripting vulnerability using a minimal, non-destructive payload. Which of the following payloads is most likely to execute JavaScript in a victim's browser when injected into the vulnerable parameter?

⚠ Common exam trap

The trap here is assuming that any special characters reflected in the response confirm XSS, when only payloads that are parsed as executable script in the browser context actually demonstrate the vulnerability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

<script>alert(document.domain)</script>

Reflected cross-site scripting occurs when user input is immediately returned by the web server without proper output encoding, allowing an attacker to inject client-side script. A script tag containing a simple alert is a reliable proof of concept because it executes in the victim's browser context when the crafted URL is visited. The other payloads target SQL injection or path traversal and do not demonstrate JavaScript execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    1' OR '1'='1

    Why it's wrong here

    This is a classic authentication bypass or SQL injection test string. It does not execute JavaScript in a victim's browser and therefore cannot confirm reflected XSS. In the search page scenario, the parameter is reflected into HTML, not used in a SQL query, so this payload would be displayed as text. It is useful for testing SQL injection but not for confirming client-side script execution.

  • ✗

    ../../../../etc/passwd

    Why it's wrong here

    This is a path traversal payload intended to access files outside the web root. It does not confirm cross-site scripting because it does not inject executable script into the HTML response. In the given search page, the parameter is reflected into HTML, so this payload would only appear as a string and would not run JavaScript. It targets file system access, a different vulnerability class than reflected XSS.

  • ✓

    <script>alert(document.domain)</script>

    Why this is correct

    This payload injects a script tag that executes in the context of the victim's browser when the reflected response is rendered, directly confirming reflected cross-site scripting. Because the parameter is reflected unencoded into the HTML body, the browser parses the script element and runs the JavaScript, causing an alert that displays the current domain. This is a standard, minimal proof-of-concept for reflected XSS in an authorized penetration test.

  • ✗

    '; DROP TABLE users; --

    Why it's wrong here

    This is a SQL injection payload designed to terminate a SQL statement and drop a table. It does not execute JavaScript in a browser and is irrelevant to confirming cross-site scripting. In the scenario, the parameter is reflected into HTML, not passed to a database query, so the payload would simply appear as text in the response and would not confirm XSS. It also risks destructive database damage, making it inappropriate for a web assessment.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.