PEN-200 Client-Side Attacks Practice Question
When testing for DOM-based XSS, where should you focus your analysis to find the vulnerable code?
⚠ Common exam trap
Candidates often look at server-side logs or traffic proxies, forgetting that DOM XSS occurs entirely within the client's browser and may never be transmitted to the server at all.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The application's source code, specifically looking for sinks like eval() or innerHTML.
DOM-based XSS occurs entirely on the client side, where JavaScript takes data from a 'source' (like the URL fragment) and passes it to a 'sink' (like innerHTML) without proper sanitization. Analyzing the client-side JavaScript code is essential to trace the data flow from these sources to the execution sinks. This is critical because the server might never see the malicious payload at all.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The server-side application logs for suspicious input patterns.
Why it's wrong here
DOM-based XSS is executed locally within the user's browser. The malicious payload often resides in the URL fragment, which is never sent to the server. Therefore, server-side logs will rarely capture the attack, making them an ineffective place to look for DOM-based vulnerability patterns.
- ✓
The application's source code, specifically looking for sinks like eval() or innerHTML.
Why this is correct
DOM XSS occurs when client-side script flows data from an untrusted source to an execution sink. By auditing the front-end JavaScript for functions like innerHTML, document.write, or eval, you can identify where data is processed dangerously, allowing you to trace the flow back to the source.
- ✗
The database queries for evidence of script injection.
Why it's wrong here
Database queries are relevant for SQL injection or stored XSS, but they do not reveal DOM-based vulnerabilities. DOM XSS is entirely browser-resident and does not involve the database or server-side application logic, making database audit logs irrelevant for identifying the root cause of this specific vulnerability.
- ✗
The server's response headers to check for security misconfigurations.
Why it's wrong here
While security headers like CSP are important for defense-in-depth, they do not help identify the vulnerable client-side code itself. The flaw is logic-based within the JavaScript implementation, which requires manual code review or dynamic debugging to find the specific path from source to sink.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.