Courseiva
Web Application Attacks →easyMultiple Choice

PEN-200 Web Application Attacks Practice Question

Which of the following describes a stored Cross-Site Scripting (XSS) attack?

⚠ Common exam trap

Candidates often confuse stored XSS with reflected XSS, failing to recognize that stored payloads reside permanently within a database to affect multiple visiting users.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A script is injected into a database and served to future users.

Stored XSS occurs when malicious scripts are permanently saved on the target server, such as in a database or comment section. Every user who visits the affected page subsequently executes the script in their browser. This is highly dangerous because the attack propagates automatically to all users, often allowing attackers to steal session cookies, perform unauthorized actions, or redirect users to malicious domains without any interaction from the victim.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A script is reflected in the URL parameters of a request.

    Why it's wrong here

    This describes Reflected XSS, where the malicious payload is part of the request sent to the server and is immediately returned in the response. Unlike stored XSS, the payload is not saved on the server and must be delivered to each victim individually, typically through social engineering links.

  • ✓

    A script is injected into a database and served to future users.

    Why this is correct

    Stored XSS involves injecting malicious code into persistent storage like a database, forum post, or profile field. When other users view the page, the server delivers the stored payload to their browsers, which then execute it. This allows for persistent, widespread impact across all users visiting the compromised page.

  • ✗

    A script is executed purely on the client-side without reaching the server.

    Why it's wrong here

    This describes DOM-based XSS, where the vulnerability exists entirely in the client-side code. The server is not involved in processing or storing the malicious payload. While it is a type of XSS, it is fundamentally different from stored XSS, which relies on backend storage and subsequent retrieval.

  • ✗

    An attacker uses a brute-force attack to guess user passwords.

    Why it's wrong here

    Brute-forcing is a credential-based attack, not an XSS vulnerability. It involves repeatedly guessing passwords to gain unauthorized access to an account. XSS is a code injection vulnerability, whereas brute-forcing is an authentication mechanism flaw. They involve completely different methodologies, tools, and exploitation techniques in a web application assessment context.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.