PEN-200 Public Exploits Practice Question
You are adapting a public Python exploit for a Windows target. The exploit was written for a different architecture and uses a hardcoded payload. Which TWO actions are MOST appropriate to make the exploit work reliably? (Choose two.)
⚠ Common exam trap
The trap here is focusing on rewriting or re-engineering the exploit when the actual blockers are a mismatched payload architecture and incorrect network parameters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the exploit's target IP address and port variables to match your listener and the victim host.
Public exploits frequently contain hardcoded payloads and network settings from the original author's environment. Regenerating the payload for the target's architecture and OS, and updating the target and callback addresses, are the two changes that directly make the exploit function against your specific host. Other modifications are unnecessary or require prior access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rewrite the exploit in C to improve execution speed against the target.
Why it's wrong here
Rewriting in another language is unnecessary and introduces new bugs. The exploit's language does not determine whether the payload executes on the target; the payload's architecture and the exploit's correctness do. Effort should focus on adapting parameters and payload rather than porting the entire script, which risks breaking working logic.
- ✗
Change the exploit's delivery mechanism from HTTP to SMB to bypass network filtering.
Why it's wrong here
Altering the delivery protocol does not address the core problems of mismatched payload architecture or incorrect network parameters. It also assumes SMB is available and permitted, which may not be true. The reliable fixes are regenerating the payload for the target and correcting the target and callback addresses, not redesigning the transport.
- ✗
Disable the target's firewall to allow the reverse shell to connect back.
Why it's wrong here
Disabling the target's firewall requires prior access and is not an adaptation step for the exploit itself. Outbound connections from the target are typically allowed, so a reverse shell often succeeds without firewall changes. This action is both unnecessary and beyond the scope of modifying the exploit to function correctly against the described target.
- ✓
Update the exploit's target IP address and port variables to match your listener and the victim host.
Why this is correct
Hardcoded network parameters are common in public exploits. If the target IP or callback port does not match your environment, the exploit either fails to reach the vulnerable service or the payload connects to the wrong host. Correcting these variables aligns the exploit with your engagement setup and ensures the reverse connection returns to your listener.
- ✓
Replace the hardcoded payload with one generated for the target's architecture and operating system.
Why this is correct
Payloads are architecture- and OS-specific. A payload compiled for x86 Linux will not execute correctly on x64 Windows. Regenerating the payload with msfvenom or a similar tool for the correct platform ensures the shellcode matches the target's execution environment, which is essential for reliable exploitation after the vulnerability is triggered.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.