PEN-200 Public Exploits Practice Question
You have identified an outdated version of a web application running on a target. You found a public exploit script for this version on Exploit-DB. Which step is most critical before executing the exploit script against the target?
⚠ Common exam trap
Test-takers often assume public exploit scripts work out-of-the-box and neglect to review target parameters, leading to unintended service crashes or execution failures in custom environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the source code to verify target parameters and modify hardcoded configurations.
Validating the exploit code is essential because public scripts often contain hardcoded IP addresses, paths, or shellcode that may not match your environment. Modifying the script ensures it executes properly, avoids unintended network traffic, and prevents potential instability on the target service. Failure to review code can lead to silent failure, false positives, or accidental service crashes, hindering your overall progress during an assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately run the script with root privileges to ensure full access.
Why it's wrong here
Running scripts with elevated privileges without review is dangerous. Malicious or poorly written code can cause irreversible system damage or security lockdowns. You must understand the payload and its potential impact on system stability before execution to ensure you do not inadvertently destroy evidence or crash the server.
- ✗
Upload the script directly to the target system via a browser-based upload form.
Why it's wrong here
Uploading directly via a browser is inefficient and lacks control. You should test the exploit locally or in a sandbox first. Without analyzing the script's logic, you have no guarantee it will interact correctly with the target's specific file system structure or environment variables, potentially leading to immediate detection.
- ✓
Review the source code to verify target parameters and modify hardcoded configurations.
Why this is correct
Reviewing source code allows you to identify hardcoded variables such as LHOST, LPORT, or specific file paths that must align with your attack machine. Customizing the script ensures that the reverse shell or exploit payload reaches the correct destination without being blocked or routed to an incorrect internal address.
- ✗
Convert the script into a binary executable using a compiler to hide its nature.
Why it's wrong here
Compiling a script into a binary does not aid in exploit functionality and adds unnecessary complexity. The primary goal is to ensure the script logic is correct for the specific target architecture and service. Obfuscation is rarely effective against modern EDR solutions and does not fix underlying logic errors.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.