Courseiva
← Back to OffSec PEN-200 / OSCP Concepts questions

Scenario-based practice

Hard Difficulty Questions

Practise OffSec PEN-200 / OSCP Concepts practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
PEN-200
exam code
OffSec
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related PEN-200 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

During an internal penetration test, you capture a NetNTLMv2 challenge-response hash from a Windows host. You want to crack it offline to recover the plaintext password. Which tool and mode should you use to maximize efficiency against this hash type?

Question 2hardmultiple choice
Full question →

During an internal Active Directory assessment, you have compromised a standard domain user account. You run BloodHound and identify that this user has the 'GenericAll' permission over a computer object named WEB01. You want to leverage this permission to compromise WEB01 and obtain administrative access to it. Which of the following is the most direct and reliable technique to achieve this?

Question 3hardmulti select
Full question →

When evaluating a web application for Cross-Site Scripting vulnerabilities during a penetration test, which TWO input contexts should you examine because they frequently lead to executable script injection?

Question 4hardmultiple choice
Full question →

You are adapting a public exploit whose payload is a reverse shell. The exploit runs and the service reports success, but your netcat listener never receives a connection. Which cause is most likely?

Question 5hardmultiple choice
Full question →

Refer to the exhibit.

```http HTTP/1.1 200 OK Server: nginx Content-Type: text/html; charset=UTF-8 Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'

<html> <body> <h1>Welcome</h1> <script>var token = '12345';</script> </body> </html> ```

Based on the HTTP response headers and body shown in the exhibit, what significant security risk is present regarding client-side attacks?

Question 6hardmultiple choice
Full question →

Which of the following describes the 'Open Redirect' vulnerability often used in phishing attacks?

Question 7hardmulti select
Full question →

You are auditing a file upload feature that restricts uploaded files based solely on extension blacklisting and client-side JavaScript validation. Which TWO techniques can you use to bypass these controls and achieve remote code execution on a Linux-based web server?

Question 8hardmulti select
Full question →

A penetration tester is investigating scheduled tasks for potential privilege escalation. Which TWO conditions must be met for a scheduled task to be successfully exploited for gaining SYSTEM privileges?

Refer to the exhibit. A penetration tester analyzing a Linux host finds the SUID binary shown in the exhibit. Running 'ltrace /usr/local/bin/check_logs' reveals that the program invokes the C library function system("tail -n 10 /var/log/syslog"). How can this SUID binary be exploited?

Exhibit

uid=1001(developer) gid=1001(developer) groups=1001(developer)
-rwsr-xr-x 1 root root 14280 Mar 12 14:00 /usr/local/bin/check_logs
Question 10hardmultiple choice
Full question →

You are performing a password audit and want to generate targeted candidate passwords based on company-specific terms, years, and common suffixes using Hashcat's rule-based engine. Which built-in Hashcat rule file applies standard capitalization toggles and appends common digit suffixes?

Question 11hardmultiple choice
Full question →

Refer to the exhibit. You are running a public exploit, but it fails with a 'Connection refused' error. What should you investigate first?

Exhibit

Error: [Errno 111] Connection refused
Target: 10.10.10.5:8080
Payload: reverse_tcp
Question 12hardmultiple choice
Full question →

You have obtained a low-privileged shell on a Windows Server 2019 machine. During enumeration, you discover that the user account you compromised has the SeBackupPrivilege enabled. You want to leverage this privilege to extract the SAM and SYSTEM registry hives for offline credential extraction. Which of the following commands correctly uses the built-in Windows utility `reg` to save these hives, and what is the required privilege?

Question 13hardmulti select
Full question →

You have compromised a service account that has the SeEnableDelegationPrivilege right on a domain controller. You want to abuse Kerberos delegation to gain access to a target server's file share. Which two steps are required to configure and exploit unconstrained delegation on a controlled computer object? (Choose two.)

Question 14hardmulti select
Full question →

You have compromised a Linux host that acts as a pivot into a segmented network. You want to use SSH remote port forwarding to expose an internal service (192.168.1.100:3389) to your attacking machine. You run the command: ssh -R 9001:192.168.1.100:3389 user@attacker.com. Which TWO statements about this setup are correct? (Choose two.)

Question 15hardmultiple choice
Full question →

You have compromised a Linux host that dual-homes between your attacking network (192.168.1.0/24) and an internal network (10.0.0.0/24). The internal network contains a server at 10.0.0.5 running an SSH service on port 22. You want to use SSH dynamic port forwarding to create a SOCKS proxy on your attacking machine, allowing you to scan the internal network with Nmap. Which command should you run on your attacking machine?

Question 16hardmultiple choice
Full question →

During a red team engagement, a tester writes a C# loader that calls the Win32 API function VirtualAllocEx to allocate memory in a remote process, writes shellcode, and creates a remote thread. The loader compiles and runs, but the endpoint's EDR blocks it before the remote thread executes. The tester confirms the EDR is hooking user-mode API functions in ntdll.dll. Which approach most directly avoids the user-mode hooks that triggered the block?

Question 17hardmulti select
Full question →

You have obtained a set of NTLM hashes from a Windows domain controller and want to perform a pass-the-hash attack to move laterally. Which TWO of the following tools can be used to authenticate to remote systems using only the NTLM hash? (Choose two.)

Question 18hardmulti select
Full question →

A penetration tester needs to deliver a Meterpreter payload to a Windows target protected by an EDR that performs both static file scanning and behavioral monitoring of process creation. The tester wants to reduce the chance of detection during initial execution while still obtaining a session. Which two techniques most directly reduce detection in this combined scenario? (Choose two.)

Question 19hardmultiple choice
Full question →

You have gained access to a Windows Server 2019 host as a low-privileged user. You discover that the system has the SeBackupPrivilege and SeRestorePrivilege enabled for your user account. You want to extract the SAM and SYSTEM registry hives to obtain password hashes for offline cracking. Which command should you use to copy the SAM hive to a location where you can access it?

Question 20hardmultiple choice
Full question →

You are performing a client-side attack against a Windows 10 workstation. The target user has Microsoft Office 2016 installed and macro execution is disabled via Group Policy. You need to execute arbitrary code when the user opens a weaponized document. Which technique is most likely to succeed?

These PEN-200 practice questions are part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style PEN-200 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.