PEN-200 Client-Side Attacks Practice Question
When evaluating a web application for Cross-Site Scripting vulnerabilities during a penetration test, which TWO input contexts should you examine because they frequently lead to executable script injection?
⚠ Common exam trap
Candidates often focus only on standard input fields, missing that HTML attributes like 'onerror' or 'onload' are frequently overlooked injection vectors that browsers process as executable JavaScript.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Input reflected directly between opening and closing HTML tags, such as <div>USER_INPUT</div>
XSS occurs when untrusted user input is rendered in an unsafe context within the HTML document. Examining input reflected directly inside HTML body tags or inside event handler attributes (like onload or onerror) are primary areas where browsers will evaluate injected strings as executable JavaScript.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Input reflected directly between opening and closing HTML tags, such as <div>USER_INPUT</div>
Why this is correct
Reflecting user input between standard HTML tags allows an attacker to supply arbitrary HTML and script tags. When the browser parses the document, it interprets the injected <script> tags as executable code rather than plain text.
- ✗
Input processed by a backend database stored procedure for primary key generation
Why it's wrong here
Database stored procedures generating primary keys never emit their output into HTML, attribute, or script contexts, so injected characters cannot reach a browser parser. It is tempting because stored procedures are a recognised injection surface, but that concerns SQL injection, where parameterised calls and least-privilege execution — not XSS context analysis — are the correct controls.
- ✓
Input placed inside HTML event handler attributes, such as <img src='x' onerror='USER_INPUT'>
Why this is correct
Event handler attributes such as onerror execute JavaScript when the event fires, so injected input breaks out of the attribute context and runs as script. This satisfies the stem's requirement for an input context frequently yielding executable injection, distinct from plain HTML body text.
- ✗
Input stored as an encrypted binary blob inside the browser local session storage
Why it's wrong here
Data stored as encrypted binary blobs in local storage is treated as static data structures by the client application. It does not get evaluated or parsed as active HTML markup unless explicitly decoded and rendered by the application DOM.
- ✗
Input utilized as a parameter value inside a server-side JSON response header without content-type sniffing
Why it's wrong here
JSON responses with proper application/json content-type headers are parsed as data objects by modern browsers rather than executed as HTML markup. Without explicit DOM rendering of the JSON values into the page, script execution cannot occur.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.