Courseiva
Public Exploits →easyMultiple Choice

PEN-200 Public Exploits Practice Question

You download a public exploit from Exploit-DB for a known vulnerability in a web application. Before running it against a client's production server, which action is the MOST appropriate next step?

⚠ Common exam trap

The trap here is trusting a public exploit because it came from a well-known repository, when repositories host community submissions that are not guaranteed safe.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the exploit's source code to understand its actions and test it in a lab environment first.

Public exploits are not inherently trustworthy. Reviewing the source reveals destructive actions, unexpected network callbacks, or hidden backdoors, and lab testing validates behavior safely. Only after understanding the exploit should it be considered for use against a production target, consistent with professional and OSCP-aligned methodology.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run the exploit immediately because Exploit-DB entries are verified by OffSec.

    Why it's wrong here

    Exploit-DB entries are community-submitted and not all are verified by OffSec. Running an untrusted exploit against production without review risks unintended damage, data loss, or introducing malware. The responsible approach is to review the code, understand its actions, and test in a controlled environment before touching production.

  • ✗

    Ask the client to disable their antivirus so the exploit runs without interference.

    Why it's wrong here

    Requesting AV disablement before understanding the exploit is premature and unprofessional. It also changes the environment in ways that may not reflect real attacker conditions. The immediate next step is to review and lab-test the code. AV evasion, if needed, is a later consideration handled within the rules of engagement.

  • ✓

    Review the exploit's source code to understand its actions and test it in a lab environment first.

    Why this is correct

    Public exploits may contain destructive payloads, hardcoded callbacks, or backdoors. Reviewing the source reveals what the code does, and testing in a lab confirms behavior without risking the client's production system. This aligns with professional penetration testing practice and the OSCP emphasis on understanding and validating tools before use.

  • ✗

    Submit the exploit to VirusTotal to confirm it is not malicious, then run it.

    Why it's wrong here

    VirusTotal flags many legitimate exploits as malicious because they contain shellcode or reverse-shell logic. A clean or flagged result does not reliably indicate safety or intent. It also uploads the file to a third party, which may violate engagement confidentiality. Source review and lab testing are more informative and safer.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.