Courseiva

PEN-200 · topic practice

Scenario practice questions

Practise OffSec PEN-200 / OSCP Concepts Scenario practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
15 questionsDomain: Scenario

What the exam tests

What to know about Scenario

Scenario questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Scenario exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Practice set

Scenario questions

15 questions · select your answer, then reveal the explanation

Question 1easymultiple choice
Read the full DNS explanation →

During external reconnaissance you collect DNS records for a target organization and find an MX record pointing to mail.example.com. You want to identify the IP addresses of other hosts in the same mail infrastructure without sending any packets directly to the target's servers. Which action best fits this passive goal?

Question 2hardmulti select
Read the full Scenario explanation →

A penetration tester needs to deliver a Meterpreter payload to a Windows target protected by an EDR that performs both static file scanning and behavioral monitoring of process creation. The tester wants to reduce the chance of detection during initial execution while still obtaining a session. Which two techniques most directly reduce detection in this combined scenario? (Choose two.)

Question 3easymultiple choice
Read the full Scenario explanation →

When reviewing 'sudo -l' output, what does the 'NOPASSWD' tag signify for the listed command?

Question 4easymultiple choice
Read the full Scenario explanation →

You identify a cron job running as root that executes a script located in a writable directory. What is the most reliable way to escalate privileges in this scenario?

Question 5easymultiple choice
Read the full Scenario explanation →

You have a Windows host with outbound internet access but want to avoid installing a full agent. You decide to use Chisel to pivot. Which statement accurately describes how Chisel establishes the tunnel in this scenario?

Question 6mediummultiple choice
Read the full Scenario explanation →

A tester is targeting a Windows machine and notices that a specific legitimate application regularly looks for a COM object that is missing from the HKEY_CURRENT_USER (HKCU) registry hive, eventually falling back to HKEY_LOCAL_MACHINE (HKLM). How can this be exploited for evasion?

Question 7hardmultiple choice
Read the full Scenario explanation →

You are testing a Java-based web application that uses the Spring framework. The application has an endpoint /api/users/{id} that returns user details in JSON. When you request /api/users/123, you receive your own details. You then request /api/users/124 and receive another user's details. The application uses a session cookie but does not implement any role-based checks on this endpoint. What is the MOST appropriate next step to demonstrate the impact of this vulnerability?

Question 8mediummultiple choice
Read the full Scenario explanation →

During an authorized penetration test of a PHP e-commerce site, you discover that the 'remember me' cookie is created with the following code: setcookie('auth', base64_encode($user_id . ':' . $role), time()+2592000); The cookie value is 'MTIzNDp1c2Vy'. You decode it to '123:user'. The application trusts this cookie for authentication on subsequent requests. What is the MOST direct way to escalate privileges to administrator?

Question 9hardmulti select
Read the full Scenario explanation →

You are testing a web application that uses a MySQL database. You suspect a UNION-based SQL injection in the 'id' parameter of a product page. The page displays product names and descriptions. Which two steps are necessary to successfully extract data using a UNION attack? (Choose two.)

Question 10mediummultiple choice
Read the full Scenario explanation →

You are developing an exploit for a Windows 32-bit application with a stack buffer overflow. You have identified a JMP ESP instruction at a static address. However, the application uses SafeSEH. Which statement is true regarding the use of JMP ESP in this scenario?

Question 11easymultiple choice
Read the full Scenario explanation →

A web application uses JSON Web Tokens for authentication. You capture a token whose header is `{"alg":"HS256","typ":"JWT"}` and payload is `{"user":"guest","role":"user"}`. The server verifies the signature with a symmetric secret. Which attack is most likely to let you forge a token with `"role":"admin"` if the application is misconfigured?

Question 12mediummultiple choice
Read the full Scenario explanation →

You are exploiting a 32-bit Windows FTP server that uses a fixed-size stack buffer and a vulnerable call to strcpy. After overwriting EIP with a JMP ESP address, you notice that your shellcode executes but the connection drops immediately without a shell. You suspect bad characters corrupted the payload. Which method is most effective for identifying all bad characters in this scenario?

Question 13hardmultiple choice
Read the full Scenario explanation →

You are exploiting a 32-bit Linux buffer overflow and have overwritten EIP with the address of a `JMP ESP` instruction located in a non-ASLR module. However, when you run the exploit, the program crashes with a segmentation fault, and no shell is obtained. You verify that the offset is correct and the JMP ESP address is accurate. What is the most likely reason for the failure?

Question 14mediummultiple choice
Read the full Scenario explanation →

While auditing a web application, you identify an endpoint that retrieves profile images via a URL parameter: 'image.php?file=profile.jpg'. Changing the parameter to 'image.php?file=/etc/passwd' returns the contents of the system password file. Which vulnerability is present, and what is the primary risk?

Question 15easymultiple choice
Read the full Scenario explanation →

During an internal assessment, you compromise a Windows host that can reach a segmented network. You want to run a SOCKS proxy on the compromised Windows host so that your Kali tools can reach internal targets through it. Which tool is specifically designed for this purpose and commonly used in PEN-200 scenarios?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Scenario sessions

Start a Scenario only practice session

Every question in these sessions is drawn from the Scenario domain — nothing else.

Related practice questions

Related PEN-200 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PEN-200 exam test about Scenario?
Scenario questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Scenario questions in a focused session?
Yes — the session launcher on this page draws every question from the Scenario domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PEN-200 topics?
Use the topic links above to move to related areas, or go back to the PEN-200 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PEN-200 exam covers. They are not copied from any real exam or dump site.