Courseiva
Client-Side Attacks →easyMultiple Choice

PEN-200 Client-Side Attacks Practice Question

When testing for DOM-based XSS, where should you focus your analysis to find the vulnerable code?

⚠ Common exam trap

Candidates often look at server-side logs or traffic proxies, forgetting that DOM XSS occurs entirely within the client's browser and may never be transmitted to the server at all.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application's source code, specifically looking for sinks like eval() or innerHTML.

DOM-based XSS occurs entirely on the client side, where JavaScript takes data from a 'source' (like the URL fragment) and passes it to a 'sink' (like innerHTML) without proper sanitization. Analyzing the client-side JavaScript code is essential to trace the data flow from these sources to the execution sinks. This is critical because the server might never see the malicious payload at all.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The server-side application logs for suspicious input patterns.

    Why it's wrong here

    DOM-based XSS is executed locally within the user's browser. The malicious payload often resides in the URL fragment, which is never sent to the server. Therefore, server-side logs will rarely capture the attack, making them an ineffective place to look for DOM-based vulnerability patterns.

  • ✓

    The application's source code, specifically looking for sinks like eval() or innerHTML.

    Why this is correct

    DOM XSS occurs when client-side script flows data from an untrusted source to an execution sink. By auditing the front-end JavaScript for functions like innerHTML, document.write, or eval, you can identify where data is processed dangerously, allowing you to trace the flow back to the source.

  • ✗

    The database queries for evidence of script injection.

    Why it's wrong here

    Database queries are relevant for SQL injection or stored XSS, but they do not reveal DOM-based vulnerabilities. DOM XSS is entirely browser-resident and does not involve the database or server-side application logic, making database audit logs irrelevant for identifying the root cause of this specific vulnerability.

  • ✗

    The server's response headers to check for security misconfigurations.

    Why it's wrong here

    While security headers like CSP are important for defense-in-depth, they do not help identify the vulnerable client-side code itself. The flaw is logic-based within the JavaScript implementation, which requires manual code review or dynamic debugging to find the specific path from source to sink.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.