PEN-200 Web Application Attacks Practice Question
What is the primary security risk of an application that fails to properly validate the 'Content-Type' header during a file upload process?
⚠ Common exam trap
Candidates often believe that checking the Content-Type header is a valid security measure, not realizing it is user-controlled data that can be easily spoofed to bypass upload filters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It enables an attacker to bypass file type restrictions to upload executable scripts.
Relying on the 'Content-Type' header is dangerous because it is sent by the client and easily spoofed. If an application uses this header to determine file safety, an attacker can upload malicious scripts disguised as images. This leads to Remote Code Execution (RCE) if the web server executes the uploaded file, making secure file upload handling a critical defense-in-depth practice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It allows attackers to perform SQL Injection attacks.
Why it's wrong here
File upload vulnerabilities are unrelated to database query manipulation. SQL injection occurs when input is used in queries, whereas file upload flaws exploit the server's file storage and execution logic. These are distinct attack vectors requiring different mitigation strategies.
- ✓
It enables an attacker to bypass file type restrictions to upload executable scripts.
Why this is correct
The Content-Type header is easily modified in an intercepting proxy. If the server trusts this header, an attacker can send a PHP script while labeling it as 'image/jpeg'. The server accepts it, potentially allowing the attacker to execute malicious code on the system.
- ✗
It prevents the server from storing large files, leading to denial of service.
Why it's wrong here
The Content-Type header does not control file size limits. While large file uploads can lead to resource exhaustion, this is an issue of request size validation and rate limiting, not header validation. The header specifically relates to file type identification, not size management.
- ✗
It exposes the server to Cross-Site Request Forgery (CSRF) attacks.
Why it's wrong here
CSRF exploits the way browsers handle cookies, not the file upload process or its metadata. Failing to validate headers during an upload does not inherently facilitate CSRF; rather, it creates a risk of malicious file execution or unauthorized storage on the server.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.