Courseiva
Client-Side Attacks →easyMultiple Choice

PEN-200 Client-Side Attacks Practice Question

What is the primary objective of a 'Clickjacking' attack?

⚠ Common exam trap

Candidates often confuse clickjacking with credential harvesting or phishing, missing the core mechanism of transparently overlaying UI elements to hijack clicks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To trick users into clicking on a hidden element, often to perform unauthorized actions.

Clickjacking tricks users into clicking something different from what they perceive, often by overlaying a hidden, malicious iframe over a legitimate page element. The objective is to force the user to perform unintended actions, like changing account settings or transferring funds, while they believe they are interacting with the benign UI. This leverages the user's existing session to execute authorized requests without their informed consent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To steal the user's session cookies through hidden JavaScript execution.

    Why it's wrong here

    Session cookie theft is typically achieved via XSS. Clickjacking focuses on UI manipulation and user interaction, not the extraction of session data. The attacker does not need to steal the cookie if they can simply trick the user into performing the desired action directly within the browser.

  • ✗

    To bypass the Same-Origin Policy by forcing cross-domain requests.

    Why it's wrong here

    Clickjacking does not bypass the Same-Origin Policy. It operates within the user's browser context by manipulating the visual presentation of the page. The actual requests are performed by the browser as normal, authenticated requests, which is why the SOP is not an obstacle for this attack.

  • ✓

    To trick users into clicking on a hidden element, often to perform unauthorized actions.

    Why this is correct

    Clickjacking involves overlaying a transparent or hidden iframe over a legitimate web page. The user thinks they are clicking a button on the visible page, but they are actually interacting with an element in the hidden iframe, leading to unintended and potentially harmful actions being executed.

  • ✗

    To inject malicious scripts into the page to capture keystrokes.

    Why it's wrong here

    Capturing keystrokes via injected scripts is a form of XSS or keylogging. Clickjacking relies on the user's mouse interactions, not the interception of keyboard input. While both are client-side threats, their mechanisms and attack vectors are entirely different in nature and execution.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.