PEN-200 Public Exploits Practice Question
You have identified a vulnerable service using an outdated version of a CMS. You successfully locate a public exploit script on GitHub. What is the most critical first step before running this script against your target?
⚠ Common exam trap
Candidates frequently rush to execute downloaded exploits immediately to save time, ignoring the risk of malicious payload execution or system instability caused by poorly written, untested third-party code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Read the source code to understand its mechanism and potential impact.
Before executing any public exploit, you must analyze the source code to understand its functionality, dependencies, and potential impact. Public exploits are often poorly written or intentionally malicious, potentially causing service crashes or backdooring the attacker machine. Understanding the payload ensures you do not inadvertently trigger unwanted side effects or trigger defensive alarms that could disrupt your assessment during the penetration testing engagement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately run the exploit script with administrative privileges.
Why it's wrong here
Executing scripts with administrative privileges without prior inspection is highly dangerous. You risk compromising your own testing machine if the script contains malicious code or backdoors. Always verify the code's integrity and purpose before elevating its execution permissions in any environment.
- ✗
Change the target IP address in the script's configuration.
Why it's wrong here
While necessary for the exploit to function, changing the target IP is secondary to verifying the script's safety. Proceeding without inspecting the code could lead to unintended consequences, such as crashing the target service or executing commands that you did not intend to run.
- ✓
Read the source code to understand its mechanism and potential impact.
Why this is correct
Analyzing the source code allows you to confirm that the exploit performs exactly what you expect. It helps identify hardcoded credentials, malicious payloads, or potential stability issues that could crash the target service, which is essential for maintaining control and stability during your assessment.
- ✗
Install all dependencies listed in the script's requirements file.
Why it's wrong here
Installing dependencies is a functional requirement, not a security one. Relying solely on the script's requirements without code review is risky. You could be introducing vulnerabilities into your own environment or executing code that performs unauthorized actions against your local host machine.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.