PEN-200 Enumeration and Reconnaissance Practice Question
Exhibit
HTTP/1.1 200 OK Server: Apache/2.4.41 (Ubuntu) Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/7.4.3
Refer to the exhibit. Based on the HTTP response headers provided, what critical information can be gathered for your reconnaissance?
⚠ Common exam trap
Candidates often ignore HTTP response headers, focusing only on the visual webpage content and missing critical server version disclosures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The web server version and PHP version are disclosed.
The headers explicitly disclose the web server (Apache 2.4.41) and the application framework (PHP 7.4.3). This is crucial intelligence because these specific versions may have known vulnerabilities or CVEs associated with them. By identifying the exact software stack, you can tailor your future exploitation efforts to target the specific weaknesses documented for these versions, significantly increasing the probability of a successful engagement and minimizing the noise generated by generic testing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The operating system is exclusively Windows.
Why it's wrong here
The header explicitly mentions Ubuntu, which is a Linux distribution. Claiming the OS is Windows contradicts the provided exhibit data, which shows a standard Linux-based software stack. Incorrectly identifying the OS would lead to attempting non-applicable exploits, wasting time and potentially triggering alarms on the target system.
- ✓
The web server version and PHP version are disclosed.
Why this is correct
The headers contain clear information about the server software, Apache 2.4.41, and the scripting engine, PHP 7.4.3. This version disclosure is a major vulnerability in itself, as it allows attackers to quickly look up public CVEs associated with these specific versions and plan their next steps accordingly.
- ✗
The database being used is Microsoft SQL Server.
Why it's wrong here
The headers show no information regarding the back-end database. PHP and Apache can interface with many databases, such as MySQL or PostgreSQL. Assuming a Microsoft SQL Server back-end based on these headers is unsupported and would likely lead to incorrect exploitation strategies during the assessment process.
- ✗
The application is currently configured for debugging mode.
Why it's wrong here
The provided headers contain typical server information and do not indicate a debug mode. Debugging headers are usually more descriptive, often revealing internal file paths or variable contents. The current headers provide no evidence to support the claim that the application is running in a debug state.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.