PEN-200 Public Exploits Practice Question
You have found a Python exploit that uses the 'requests' library but your target machine only has standard Python installed. What is your best course of action?
⚠ Common exam trap
Candidates often waste time attempting to install missing Python packages using pip on an isolated target, which typically results in permission errors or network connectivity issues that prevent the exploit from running.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the script to use standard Python libraries instead.
When a public exploit has unmet dependencies, the most efficient approach is to rewrite the exploit to use standard libraries or ensure the dependency is met in a way that doesn't disrupt the target. In an exam, you often cannot install external packages on the target. Therefore, porting the functionality to native libraries like 'urllib' ensures your exploit remains portable and functional without requiring additional, potentially unavailable, software installations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Upload the library to the target machine.
Why it's wrong here
Uploading external libraries to a target machine is risky and often forbidden or impossible due to security restrictions. It can also leave artifacts that compromise your stealth. It is always better to modify your exploit to work with the tools already available on the target system.
- ✓
Modify the script to use standard Python libraries instead.
Why this is correct
Rewriting the exploit to use native libraries is the most reliable method for ensuring execution in restrictive environments. It removes the dependency on external packages, making the script more robust and independent of the specific environment's pre-installed tools, which is crucial for successful exploitation in an exam.
- ✗
Install the library on your own machine and hope it works.
Why it's wrong here
Installing the library on your own machine only solves the issue for your local environment, not the target. If the exploit relies on the library to interact with the target, the dependency must be addressed in the code itself, not just on your local workstation.
- ✗
Give up on this exploit and find a different one.
Why it's wrong here
Giving up too easily is not the goal of a penetration test. Often, the best exploit for a vulnerability is the one you have, and minor modifications like porting to standard libraries are standard tasks for an OSCP examiner to demonstrate technical problem-solving and deep understanding.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.