PEN-200 Public Exploits Practice Question
When modifying a public exploit to fit your specific target, which TWO of the following actions are considered best practices? (Choose TWO)
⚠ Common exam trap
Candidates often suggest running the exploit exactly as downloaded. You must always update connection parameters and payloads to match your specific target environment to ensure success and avoid crashes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Updating the hardcoded IP address and port to match your target.
Modifying public exploits is a common task that requires precision to ensure the exploit succeeds without crashing the service. Adjusting parameters like the payload and connection information is essential for success. Properly testing these changes in a lab environment first prevents accidental service downtime or triggering defensive alerts during the actual assessment, ensuring the exploitation process is methodical, predictable, and aligned with your testing objectives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Updating the hardcoded IP address and port to match your target.
Why this is correct
Hardcoded values in public exploits are specific to the original researcher's environment. Updating these to match your current target is mandatory for the exploit to reach the intended destination. Failing to do this will result in the exploit attempting to connect to an irrelevant host.
- ✗
Changing the exploit code to use a different programming language entirely.
Why it's wrong here
Rewriting an exploit in a different language is unnecessary and prone to error. Unless you have deep expertise in both the original language and the target language, you are likely to introduce bugs that render the exploit non-functional or unstable in the testing environment.
- ✓
Replacing the default payload with your own reverse shell payload.
Why this is correct
Public exploits often include default payloads that may not suit your network configuration or listener setup. Replacing them with a verified reverse shell that matches your listener ensures you receive the callback successfully, which is a fundamental requirement for achieving a stable remote command execution.
- ✗
Deleting all comments to make the exploit run faster.
Why it's wrong here
Comments do not impact execution speed in most interpreted languages. Removing them only makes the code harder to debug and understand. Keeping documentation within the exploit code helps you troubleshoot issues if the exploitation attempt fails during your live assessment or testing phase.
- ✗
Adding complex obfuscation to bypass all possible firewalls.
Why it's wrong here
Adding unnecessary obfuscation can break the logic of the exploit script. Unless the environment requires it for a specific reason, keep the code as simple as possible to ensure it remains functional and easy to debug while you are in the middle of your assessment.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.