Courseiva
Client-Side Attacks →mediumMultiple Choice

PEN-200 Client-Side Attacks Practice Question

Which property of a URL is most commonly used as a source for DOM-based XSS because it is not sent to the server?

⚠ Common exam trap

Test-takers frequently guess standard query parameters or HTTP headers, forgetting that URL fragments are client-side only and never transmitted to servers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The URL fragment (everything after the # character).

The URL fragment (the part after the # character) is strictly handled by the browser and is never included in the HTTP request sent to the server. Because developers often assume this data is 'safe' or ignored by the backend, they frequently fail to sanitize it before using it in client-side operations, creating an ideal vector for DOM-based XSS attacks that bypass traditional WAFs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The query string (everything after the ? character).

    Why it's wrong here

    The query string is sent to the server as part of the HTTP request. While it can be a source for DOM XSS, it is also a primary target for server-side reflected XSS. It is not the most unique characteristic of DOM-based vulnerabilities compared to the fragment.

  • ✓

    The URL fragment (everything after the # character).

    Why this is correct

    The fragment identifier is never sent to the server, making it invisible to server-side security controls. This allows attackers to manipulate the client-side state without triggering backend alerts, making it the most common source for DOM XSS where the payload is handled entirely within the browser.

  • ✗

    The HTTP Referer header.

    Why it's wrong here

    The Referer header is sent to the server by the browser. While it can be logged and inspected, it is not a direct input source for most DOM XSS scenarios. It is typically used for tracking purposes rather than driving client-side script logic that results in DOM injection.

  • ✗

    The user-agent string.

    Why it's wrong here

    The user-agent is sent in every HTTP request. While it can be manipulated, it is not a common source for DOM XSS, which relies on inputs that control page structure or behavior. DOM XSS sources are typically dynamic elements on the page or components of the URL.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.