Courseiva
Public Exploits →hardMultiple Choice

PEN-200 Public Exploits Practice Question

During an internal assessment, you find a public exploit for a Jenkins script console vulnerability. The exploit sends a Groovy script to /script via a POST request. When you run it, the server returns HTTP 403. The Jenkins version matches the vulnerable range, and the endpoint is reachable. Which is the MOST likely reason the exploit fails?

⚠ Common exam trap

The trap here is assuming that a version match guarantees exploitability, when access controls can block the request before the vulnerable code is ever reached.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The exploit requires an authenticated session, and the request is being rejected due to missing or invalid credentials.

Jenkins protects the script console with authentication and authorization. Even on a vulnerable version, an unauthenticated request to /script is rejected with 403 before any Groovy executes. The exploit must include a valid session or API token belonging to a user with administrative rights. Version matching alone does not bypass access controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The exploit requires an authenticated session, and the request is being rejected due to missing or invalid credentials.

    Why this is correct

    The Jenkins script console at /script requires authentication and administrative privileges. An unauthenticated POST returns 403. The exploit likely expects a valid session cookie or API token. Without it, Jenkins denies access before evaluating the Groovy code, regardless of version. Supplying valid credentials or a token is the necessary fix.

  • ✗

    The target uses HTTPS and the exploit is sending plaintext HTTP requests to port 8080.

    Why it's wrong here

    A protocol mismatch would more likely produce a connection error, a redirect, or an SSL handshake failure rather than a clean 403 from Jenkins. If the exploit reached an HTTP listener, Jenkins would respond. A 403 specifically indicates the request was understood but denied by authorization logic, pointing to authentication rather than transport.

  • ✗

    The Groovy script contains syntax errors that Jenkins rejects at parse time.

    Why it's wrong here

    A syntax error in the Groovy payload would typically result in a 500 error or an error message in the response body, not a 403. Jenkins parses the script after authentication and authorization checks pass. A 403 indicates the request is denied before script execution, so the payload content is not the cause of this specific failure.

  • ✗

    The Groovy payload is blocked by a Web Application Firewall rule matching common reverse-shell strings.

    Why it's wrong here

    A WAF might block the request, but the scenario describes a direct Jenkins response. Jenkins itself returns 403 for unauthorized access to protected endpoints. While a WAF could be present, the more direct and common explanation for a 403 on /script is the absence of an authenticated administrative session, which the exploit must supply.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.