PEN-200 Public Exploits Practice Question
You download a public exploit for a known vulnerability from an untrusted source. Before running it against a client's production system, what is the most important action to take?
⚠ Common exam trap
The trap here is assuming that sandbox testing or hash verification is sufficient, when neither guarantees the exploit is free of malicious behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the exploit's source code to understand its actions and check for malicious payloads.
Reviewing the exploit's source code is the most important step because it reveals exactly what the code will execute. Permission and sandboxing are valuable but secondary to understanding the code, which protects both the client and the tester from unintended consequences.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check the exploit's file hash against online databases to confirm it is known.
Why it's wrong here
Hash lookups can indicate whether a file is recognized, but a novel or modified exploit will not appear in databases. This does not substitute for understanding the code's behavior, and a known hash does not guarantee the exploit is safe.
- ✗
Run the exploit in a sandboxed virtual machine first to see if it works.
Why it's wrong here
Testing in a sandbox is useful but does not replace code review. A sandbox may not reveal all malicious behavior, especially if the exploit targets external systems or uses delayed execution, and it does not tell you what the exploit is actually doing.
- ✓
Review the exploit's source code to understand its actions and check for malicious payloads.
Why this is correct
Auditing the source code is critical because public exploits from untrusted sources may contain backdoors, additional malicious payloads, or destructive commands. Understanding what the exploit does before execution protects both the client's environment and your own testing platform.
- ✗
Ask the client for permission to run the exploit on their production system.
Why it's wrong here
Authorization is necessary but does not address the security risk of running unreviewed code. Even with permission, executing a malicious exploit could damage the client's systems or compromise your own infrastructure, so code review must come first.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.