PEN-200 Public Exploits Practice Question
Exhibit
Error: [Errno 111] Connection refused Target: 10.10.10.5:8080 Payload: reverse_tcp
Refer to the exhibit. You are running a public exploit, but it fails with a 'Connection refused' error. What should you investigate first?
⚠ Common exam trap
Candidates often immediately assume their payload syntax or exploit code is broken when seeing a 'Connection refused' error, rather than checking if the port is even open or firewalled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The service availability and network path to the target.
A 'Connection refused' error usually indicates that the target port is not open, the service is not running, or a firewall is blocking the connection. Investigating the network connectivity and service status using tools like Nmap or netcat is essential. This allows you to confirm the service is actually reachable and running on the expected port before assuming the exploit itself is flawed or the payload is failing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The exploit's payload encoding settings.
Why it's wrong here
Payload encoding affects how data is transmitted to bypass filters, not the initial network connection. If you cannot connect to the port, the payload never reaches the service. You must verify connectivity before worrying about payload-specific issues like encoding or bypassing security controls.
- ✓
The service availability and network path to the target.
Why this is correct
Before troubleshooting the exploit, you must confirm the service is actually listening on the target port. A 'Connection refused' error suggests the port is closed or filtered. Verifying network connectivity ensures you are not wasting time on an exploit that has no chance of succeeding.
- ✗
The exploit's memory address offsets.
Why it's wrong here
Memory offsets are only relevant after you have successfully connected to the service and started the exploitation process. A network-level error indicates that the connection has not even been established, making memory address issues irrelevant until the underlying connectivity problem is resolved.
- ✗
The target's operating system version.
Why it's wrong here
While the OS version is important, it is not the immediate cause of a 'Connection refused' error. This error is specific to network communication. You should first focus on port status and service availability before diving into environmental differences like the specific OS running on the target.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.