Courseiva
Public Exploits →mediumMultiple Choice

PEN-200 Public Exploits Practice Question

You have identified an outdated version of a web application running on a target. You found a public exploit script for this version on Exploit-DB. Which step is most critical before executing the exploit script against the target?

⚠ Common exam trap

Test-takers often assume public exploit scripts work out-of-the-box and neglect to review target parameters, leading to unintended service crashes or execution failures in custom environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the source code to verify target parameters and modify hardcoded configurations.

Validating the exploit code is essential because public scripts often contain hardcoded IP addresses, paths, or shellcode that may not match your environment. Modifying the script ensures it executes properly, avoids unintended network traffic, and prevents potential instability on the target service. Failure to review code can lead to silent failure, false positives, or accidental service crashes, hindering your overall progress during an assessment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately run the script with root privileges to ensure full access.

    Why it's wrong here

    Running scripts with elevated privileges without review is dangerous. Malicious or poorly written code can cause irreversible system damage or security lockdowns. You must understand the payload and its potential impact on system stability before execution to ensure you do not inadvertently destroy evidence or crash the server.

  • ✗

    Upload the script directly to the target system via a browser-based upload form.

    Why it's wrong here

    Uploading directly via a browser is inefficient and lacks control. You should test the exploit locally or in a sandbox first. Without analyzing the script's logic, you have no guarantee it will interact correctly with the target's specific file system structure or environment variables, potentially leading to immediate detection.

  • ✓

    Review the source code to verify target parameters and modify hardcoded configurations.

    Why this is correct

    Reviewing source code allows you to identify hardcoded variables such as LHOST, LPORT, or specific file paths that must align with your attack machine. Customizing the script ensures that the reverse shell or exploit payload reaches the correct destination without being blocked or routed to an incorrect internal address.

  • ✗

    Convert the script into a binary executable using a compiler to hide its nature.

    Why it's wrong here

    Compiling a script into a binary does not aid in exploit functionality and adds unnecessary complexity. The primary goal is to ensure the script logic is correct for the specific target architecture and service. Obfuscation is rarely effective against modern EDR solutions and does not fix underlying logic errors.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.