20+ practice questions focused on Buffer Overflow Fundamentals — one of the most tested topics on the OffSec PEN-200 / OSCP Concepts exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Buffer Overflow Fundamentals PracticeIn the context of the PEN-200, why is the 'JMP ESP' instruction considered the 'gold standard' for stack-based overflows?
Explanation: JMP ESP is the gold standard because it effectively redirects the CPU to the current location of the stack pointer. Since the attacker has already filled the stack with their shellcode, this instruction acts as a reliable bridge. It is frequently found in common system DLLs, making it easily accessible for redirecting the instruction pointer to the shellcode without needing to know the exact, changing memory address of the stack buffer.
You are developing an exploit for a 32-bit Windows application. After sending a 5000-byte payload, you observe that the EIP value is 0x41414141. However, your payload contains no 'A' characters after byte 2000. What is the most likely reason for this EIP value?
Explanation: The EIP value 0x41414141 indicates that the register was overwritten with 'A' characters. Since the current payload lacks 'A's after byte 2000, the value must originate from a prior state. In Windows debugging, if the service is not restarted between tests, the memory may retain previous data. Therefore, the crash is likely from an earlier payload. Restarting the service and resending the current payload would clarify the true offset.
You are exploiting a stack-based buffer overflow on a Linux x86-64 binary. You have determined the offset to overwrite the return address. Which TWO of the following steps are essential to achieve reliable code execution? (Choose two.)
Explanation: To reliably execute a shell via a buffer overflow on x86-64 Linux, you typically need to control RDI to pass the argument to system(), and you need the address of system() or a one-gadget. These steps bypass ASLR and NX. Executable stack or NOP sleds are not essential and are often unreliable.
You are preparing to exploit a stack-based buffer overflow in a 32-bit Windows application. You have identified the offset to EIP and found a reliable JMP ESP instruction. Which TWO of the following steps are essential to ensure the shellcode executes successfully? (Choose two.)
Explanation: The essential steps are to ensure the JMP ESP address is free of bad characters and that the shellcode is placed immediately after the return address so ESP points to it. A NOP sled is not required because JMP ESP provides a direct jump, and encoding or disabling ASLR are not universally necessary. These two steps guarantee that the overwrite is clean and execution flows into the shellcode.
You are exploiting a stack-based buffer overflow in a Linux x86 binary. The binary has NX enabled, but you have identified a way to leak a stack address. You plan to use a return-to-libc attack to call system("/bin/sh"). Which TWO of the following are required to successfully execute this attack? (Choose two.)
Explanation: Return-to-libc on Linux requires overwriting the return address with the address of system() and arranging for its argument to point to "/bin/sh". The offset to the return address is a given from the overflow analysis. JMP ESP and POP POP RET are irrelevant because they pertain to different exploitation techniques and platforms. Thus, the essential components are the system() address and a pointer to the command string.
+15 more Buffer Overflow Fundamentals questions available
Practice all Buffer Overflow Fundamentals questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Buffer Overflow Fundamentals. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Buffer Overflow Fundamentals questions on the PEN-200 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Buffer Overflow Fundamentals is tested as part of the OffSec PEN-200 / OSCP Concepts blueprint. Practicing with targeted Buffer Overflow Fundamentals questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free PEN-200 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Buffer Overflow Fundamentals is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Buffer Overflow Fundamentals practice session with instant scoring and detailed explanations.
Start Buffer Overflow Fundamentals Practice →