Courseiva
← Back to OffSec PEN-200 / OSCP Concepts questions

Scenario-based practice

Troubleshooting Scenario Questions

Practise OffSec PEN-200 / OSCP Concepts practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

5
scenario questions
PEN-200
exam code
OffSec
vendor

Scenario guide

How to approach troubleshooting scenario questions

These questions describe a network symptom and ask you to identify the root cause or the correct fix. They appear across all certification exams and reward systematic thinking over memorisation. The best candidates follow a consistent troubleshooting framework even under time pressure.

Quick answer

Troubleshooting Scenario Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related PEN-200 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Refer to the exhibit. You are running a public exploit, but it fails with a 'Connection refused' error. What should you investigate first?

Exhibit

Error: [Errno 111] Connection refused
Target: 10.10.10.5:8080
Payload: reverse_tcp
Question 2easymultiple choice
Full question →

You are analyzing a target web application that reflects user input directly into an HTML attribute without proper sanitization. Which vulnerability class should you primarily investigate for exploitation?

Question 3mediummultiple choice
Full question →

What is the primary security risk of an application that fails to properly validate the 'Content-Type' header during a file upload process?

Question 4hardmultiple choice
Full question →

You are exploiting a buffer overflow in a 32-bit Windows application and have overwritten EIP with a JMP ESP address. However, when the shellcode executes, it fails to establish a reverse shell, and the application crashes. You suspect that the shellcode contains bad characters. Which of the following is the most effective way to identify bad characters in the shellcode?

Question 5mediummultiple choice
Full question →

You have gained a foothold on an internal Linux host (10.10.10.20) that can reach a segregated network containing a web server at 192.168.100.50:80. Your attack machine cannot reach 192.168.100.50 directly. You want to use the compromised host to forward traffic from your machine's local port 8080 to 192.168.100.50:80. Which SSH command should you run from your attack machine?

These PEN-200 practice questions are part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style PEN-200 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.