PEN-200 Client-Side Attacks Practice Question
You are assessing a web application that uses a strict Content Security Policy (CSP) with nonce-based script-src. You discover a reflected XSS vulnerability where your input is inserted into an existing <script> block that already has a valid nonce. Which action would most likely allow your JavaScript to execute despite the CSP?
⚠ Common exam trap
The trap here is focusing on creating new script tags or guessing nonces, while overlooking that the existing nonce-protected script block can be abused by injecting code directly into it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inject JavaScript code directly into the existing script block, leveraging the valid nonce.
The most effective action is to inject JavaScript directly into the existing script block that already carries a valid nonce. Since the CSP trusts scripts with that nonce, any code within that block executes without violation. This bypasses the need to create new script elements or guess nonces. It exploits the fact that the application reflects user input into a trusted script context, allowing arbitrary code execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Inject JavaScript code directly into the existing script block, leveraging the valid nonce.
Why this is correct
Because the existing script block already has a valid nonce, any JavaScript injected inside it is considered trusted by the CSP. By breaking out of the current JavaScript context (e.g., closing a string or statement) and appending your code, you can execute arbitrary JavaScript without triggering CSP violations. This is a common bypass when user input is reflected into a nonce-protected script block.
- ✗
Inject a new <script> tag with a guessed nonce value.
Why it's wrong here
Nonces are cryptographically random and unique per response, so guessing a valid nonce is infeasible. Even if you could predict it, the CSP would only allow scripts with the exact nonce. Injecting a new script tag with an incorrect nonce will be blocked by the browser, so this approach fails. The vulnerability lies in the existing script block, not in creating a new one.
- ✗
Use a data: URI in an iframe to execute JavaScript.
Why it's wrong here
CSP often restricts frame-src and script-src, and data: URIs are typically blocked for script execution. Even if an iframe were allowed, the JavaScript inside a data: URI would be subject to the CSP of the parent page if the iframe is same-origin, or blocked if cross-origin. This approach does not leverage the existing nonce and would likely be blocked by the strict CSP.
- ✗
Break out of the existing script context and inject a new script element without a nonce.
Why it's wrong here
A new script element without a nonce will be blocked by the nonce-based CSP. The CSP requires that all script elements have a valid nonce. Breaking out and adding a script tag would not execute because the browser enforces the policy. This method would only work if the CSP were absent or misconfigured, which is not the case here.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.