Courseiva
Client-Side Attacks →mediumMultiple Select

PEN-200 Client-Side Attacks Practice Question

You are performing a client-side attack against a target web application that uses a Content Security Policy (CSP) with the directive `script-src 'self'`. Which TWO techniques are most likely to bypass this CSP and execute JavaScript in a victim’s browser? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any script delivery technique bypasses CSP, when only those that result in a same-origin script source are permitted by script-src 'self'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exploiting a JSONP endpoint on the target domain that reflects a callback parameter into executable JavaScript.

A CSP with script-src 'self' trusts scripts loaded from the target’s own origin. Therefore, an attacker who can host or reflect JavaScript on that origin bypasses the policy. Uploading a JavaScript file and loading it via a script tag, or abusing a same-origin JSONP endpoint, both result in script execution from a trusted origin. External scripts, inline scripts, and data URIs are blocked because they do not match 'self'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Exploiting a JSONP endpoint on the target domain that reflects a callback parameter into executable JavaScript.

    Why this is correct

    A JSONP endpoint on the same origin returns JavaScript that calls a user-supplied callback. Because the script is served from the target origin, script-src 'self' permits it. The attacker can craft a callback that executes arbitrary code, effectively using the trusted origin to bypass the CSP. This is a classic same-origin script gadget.

  • ✗

    Using an open redirect on the target domain to load a script from an external domain.

    Why it's wrong here

    An open redirect changes the navigation destination but does not change the origin of the script being loaded. The browser evaluates the final URL’s origin for CSP. If the redirect leads to an external domain, the script’s origin is external and script-src 'self' blocks it. The redirect itself does not make the external script same-origin.

  • ✗

    Using a data: URI in a script tag to embed the JavaScript payload.

    Why it's wrong here

    Data URIs are not considered same-origin by script-src 'self'. They have a unique opaque origin, so the policy does not permit them. Unless the CSP explicitly includes data: in the script-src directive, the browser blocks the script. This option would require a misconfigured policy that allows data: sources.

  • ✓

    Hosting a malicious JavaScript file on the target’s own domain via an upload feature, then loading it with a script tag.

    Why this is correct

    The directive script-src 'self' allows scripts from the same origin. If an attacker can upload a file to the target domain and serve it as JavaScript, the browser will treat it as same-origin and execute it. This bypasses the CSP because the policy trusts the origin, not the specific script content or upload path.

  • ✗

    Injecting an inline script tag with the payload directly into the HTML.

    Why it's wrong here

    Inline script tags are blocked by script-src 'self' unless 'unsafe-inline' is also present. The policy allows only external scripts from the same origin. An inline script has no source URL, so it is not covered by 'self' and will be refused. This technique would only work if the CSP included 'unsafe-inline' or a matching nonce.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.