Courseiva
Client-Side Attacks →hardMultiple Choice

PEN-200 Client-Side Attacks Practice Question

You are assessing a web application that uses a strict Content Security Policy (CSP) with nonce-based script-src. You discover a reflected XSS vulnerability where your input is inserted into an existing <script> block that already has a valid nonce. Which action would most likely allow your JavaScript to execute despite the CSP?

⚠ Common exam trap

The trap here is focusing on creating new script tags or guessing nonces, while overlooking that the existing nonce-protected script block can be abused by injecting code directly into it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inject JavaScript code directly into the existing script block, leveraging the valid nonce.

The most effective action is to inject JavaScript directly into the existing script block that already carries a valid nonce. Since the CSP trusts scripts with that nonce, any code within that block executes without violation. This bypasses the need to create new script elements or guess nonces. It exploits the fact that the application reflects user input into a trusted script context, allowing arbitrary code execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Inject JavaScript code directly into the existing script block, leveraging the valid nonce.

    Why this is correct

    Because the existing script block already has a valid nonce, any JavaScript injected inside it is considered trusted by the CSP. By breaking out of the current JavaScript context (e.g., closing a string or statement) and appending your code, you can execute arbitrary JavaScript without triggering CSP violations. This is a common bypass when user input is reflected into a nonce-protected script block.

  • ✗

    Inject a new <script> tag with a guessed nonce value.

    Why it's wrong here

    Nonces are cryptographically random and unique per response, so guessing a valid nonce is infeasible. Even if you could predict it, the CSP would only allow scripts with the exact nonce. Injecting a new script tag with an incorrect nonce will be blocked by the browser, so this approach fails. The vulnerability lies in the existing script block, not in creating a new one.

  • ✗

    Use a data: URI in an iframe to execute JavaScript.

    Why it's wrong here

    CSP often restricts frame-src and script-src, and data: URIs are typically blocked for script execution. Even if an iframe were allowed, the JavaScript inside a data: URI would be subject to the CSP of the parent page if the iframe is same-origin, or blocked if cross-origin. This approach does not leverage the existing nonce and would likely be blocked by the strict CSP.

  • ✗

    Break out of the existing script context and inject a new script element without a nonce.

    Why it's wrong here

    A new script element without a nonce will be blocked by the nonce-based CSP. The CSP requires that all script elements have a valid nonce. Breaking out and adding a script tag would not execute because the browser enforces the policy. This method would only work if the CSP were absent or misconfigured, which is not the case here.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.