Courseiva
Public Exploits →hardMultiple Choice

PEN-200 Public Exploits Practice Question

Exhibit

Error: [Errno 111] Connection refused
Target: 10.10.10.5:8080
Payload: reverse_tcp

Refer to the exhibit. You are running a public exploit, but it fails with a 'Connection refused' error. What should you investigate first?

⚠ Common exam trap

Candidates often immediately assume their payload syntax or exploit code is broken when seeing a 'Connection refused' error, rather than checking if the port is even open or firewalled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The service availability and network path to the target.

A 'Connection refused' error usually indicates that the target port is not open, the service is not running, or a firewall is blocking the connection. Investigating the network connectivity and service status using tools like Nmap or netcat is essential. This allows you to confirm the service is actually reachable and running on the expected port before assuming the exploit itself is flawed or the payload is failing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The exploit's payload encoding settings.

    Why it's wrong here

    Payload encoding affects how data is transmitted to bypass filters, not the initial network connection. If you cannot connect to the port, the payload never reaches the service. You must verify connectivity before worrying about payload-specific issues like encoding or bypassing security controls.

  • ✓

    The service availability and network path to the target.

    Why this is correct

    Before troubleshooting the exploit, you must confirm the service is actually listening on the target port. A 'Connection refused' error suggests the port is closed or filtered. Verifying network connectivity ensures you are not wasting time on an exploit that has no chance of succeeding.

  • ✗

    The exploit's memory address offsets.

    Why it's wrong here

    Memory offsets are only relevant after you have successfully connected to the service and started the exploitation process. A network-level error indicates that the connection has not even been established, making memory address issues irrelevant until the underlying connectivity problem is resolved.

  • ✗

    The target's operating system version.

    Why it's wrong here

    While the OS version is important, it is not the immediate cause of a 'Connection refused' error. This error is specific to network communication. You should first focus on port status and service availability before diving into environmental differences like the specific OS running on the target.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.