Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

Exhibit

HTTP/1.1 200 OK
Server: Apache/2.4.41 (Ubuntu)
Content-Type: text/html; charset=UTF-8
X-Powered-By: PHP/7.4.3

Refer to the exhibit. Based on the HTTP response headers provided, what critical information can be gathered for your reconnaissance?

⚠ Common exam trap

Candidates often ignore HTTP response headers, focusing only on the visual webpage content and missing critical server version disclosures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The web server version and PHP version are disclosed.

The headers explicitly disclose the web server (Apache 2.4.41) and the application framework (PHP 7.4.3). This is crucial intelligence because these specific versions may have known vulnerabilities or CVEs associated with them. By identifying the exact software stack, you can tailor your future exploitation efforts to target the specific weaknesses documented for these versions, significantly increasing the probability of a successful engagement and minimizing the noise generated by generic testing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The operating system is exclusively Windows.

    Why it's wrong here

    The header explicitly mentions Ubuntu, which is a Linux distribution. Claiming the OS is Windows contradicts the provided exhibit data, which shows a standard Linux-based software stack. Incorrectly identifying the OS would lead to attempting non-applicable exploits, wasting time and potentially triggering alarms on the target system.

  • ✓

    The web server version and PHP version are disclosed.

    Why this is correct

    The headers contain clear information about the server software, Apache 2.4.41, and the scripting engine, PHP 7.4.3. This version disclosure is a major vulnerability in itself, as it allows attackers to quickly look up public CVEs associated with these specific versions and plan their next steps accordingly.

  • ✗

    The database being used is Microsoft SQL Server.

    Why it's wrong here

    The headers show no information regarding the back-end database. PHP and Apache can interface with many databases, such as MySQL or PostgreSQL. Assuming a Microsoft SQL Server back-end based on these headers is unsupported and would likely lead to incorrect exploitation strategies during the assessment process.

  • ✗

    The application is currently configured for debugging mode.

    Why it's wrong here

    The provided headers contain typical server information and do not indicate a debug mode. Debugging headers are usually more descriptive, often revealing internal file paths or variable contents. The current headers provide no evidence to support the claim that the application is running in a debug state.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.