Courseiva
Public Exploits →easyMultiple Choice

PEN-200 Public Exploits Practice Question

You download a public exploit archive from an unknown source. Before using it in the PEN-200 lab, which step best protects your own attacking machine from a trojanized exploit?

⚠ Common exam trap

The trap here is trusting a clean antivirus scan or an unknown-hash result as evidence of safety, when both are consistent with a trojanized exploit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run the exploit inside a disposable virtual machine with no shared folders and no host network bridging.

Isolating the exploit in a disposable VM without shared folders or bridged networking contains any malicious behavior and prevents it from reaching the host or other lab systems. Antivirus scans, hash lookups, and author claims all fail to prove safety because a trojanized exploit is designed to evade exactly those checks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Scan the archive with the antivirus installed on your host before extracting it.

    Why it's wrong here

    Antivirus signatures often miss newly trojanized exploit code because the malicious component may be a custom loader or an obfuscated script. A clean scan therefore provides false confidence, and if the archive does contain a working payload, extracting and running it on the host still exposes your primary system to compromise.

  • ✗

    Read the exploit's comments and README to confirm the author claims it is safe.

    Why it's wrong here

    Author claims are unverifiable and are exactly what a malicious archive would include to lower your guard. Documentation cannot demonstrate that the code does only what it claims, so relying on it leaves the host exposed to any hidden behavior the archive actually performs when executed.

  • ✗

    Check the exploit's file hash against an online malware database and proceed if it is unknown.

    Why it's wrong here

    An unknown hash simply means the file has not been catalogued; it says nothing about whether the code is safe. Proceeding on an unknown result is the opposite of caution, because novel trojanized exploits are precisely the files that would not yet appear in any database, so this check adds no real protection.

  • ✓

    Run the exploit inside a disposable virtual machine with no shared folders and no host network bridging.

    Why this is correct

    An isolated disposable VM confines any malicious behavior to a system you can discard, while the lack of shared folders and bridged networking prevents the malware from reaching your host files or the broader network. This containment strategy is the most reliable protection when the trustworthiness of an exploit archive cannot be established.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.