Courseiva
Client-Side Attacks →mediumMultiple Choice

PEN-200 Client-Side Attacks Practice Question

You are conducting a client-side attack using a weaponized Microsoft Office document containing a malicious VBA macro. Which user interaction and application setting combination is required for the macro to execute successfully by default?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user must click 'Enable Content' in the security banner after the file opens in Protected View

By default, modern Microsoft Office applications block macros in files obtained from the internet using Office Protected View and Antimalware Scan Interface integrations. Users must explicitly click 'Enable Content' in the Security Warning banner after opening the file for the VBA code to run.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user must double-click the document while holding down the Shift key to bypass AutoOpen restrictions

    Why it's wrong here

    Holding down the Shift key while opening an Office document actually prevents auto-executing macros like AutoOpen or Document_Open from running. This is a legitimate troubleshooting and security feature built into Office to help users bypass malicious automation.

  • ✗

    The file must be saved in the local startup directory and the user must open the application normally

    Why it's wrong here

    Saving to the startup directory does not bypass Office macro security; Protected View and macro blocking still apply unless the location is a Trusted Location. That placement suits persistence across logons, not the default execution path for a weaponised document.

  • ✓

    The user must click 'Enable Content' in the security banner after the file opens in Protected View

    Why this is correct

    Modern Microsoft Office suites isolate downloaded documents in Protected View and display a yellow security banner warning about active content. Execution only occurs if the user explicitly overrides these security controls by clicking the enable button.

  • ✗

    The target workstation must have macro auditing disabled via Group Policy Objects before execution

    Why it's wrong here

    Group Policy Objects are administrative settings managed by domain controllers, not user actions required for exploit delivery. Exploiting a target via phishing relies on bypassing user-level trust boundaries rather than modifying enterprise domain group policies.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.