200-201 Network Intrusion Analysis Practice Question
An analyst is reviewing PCAP from a network intrusion. The attacker used a payload with ROP gadgets and shellcode. Which TWO exploitation indicators are associated with this attack? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ROP gadgets
Shellcode is the actual executable code injected; ROP gadgets are used to bypass DEP by chaining existing code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ROP gadgets
Why this is correct
ROP gadgets are small instruction sequences used to chain calls.
- ✗
NOP sled
Why it's wrong here
NOP sleds are used with buffer overflows, but not necessarily with ROP.
- ✗
Heap spray
Why it's wrong here
Heap spray is a separate technique to allocate memory, not directly indicated by ROP.
- ✓
Shellcode
Why this is correct
Shellcode is the malicious code to be executed.
- ✗
DNS tunnelling
Why it's wrong here
DNS tunnelling is a communication technique, not exploitation.
Go deeper
Related to this question
About these practice questions
One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.