Courseiva
hardMultiple Choice

PT0-002 Practice Question: A penetration tester has successfully exploited a…

A penetration tester has successfully exploited a buffer overflow vulnerability in a Linux binary. However, the binary has Data Execution Prevention (DEP) enabled and Address Space Layout Randomization (ASLR) disabled. Which exploitation technique is MOST appropriate to achieve code execution in this environment?

⚠ Common exam trap

CompTIA often tests the misconception that DEP can be bypassed by simply injecting shellcode onto the stack, ignoring that DEP explicitly prevents execution from non-executable pages, making ROP or similar code-reuse techniques mandatory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Return-oriented programming (ROP) to bypass DEP

Return-oriented programming (ROP) is the most appropriate technique because DEP marks the stack and heap as non-executable, preventing direct shellcode injection. With ASLR disabled, the attacker can reliably locate and chain small instruction sequences (gadgets) from the binary or loaded libraries to achieve arbitrary code execution without needing executable memory regions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Return-oriented programming (ROP) to bypass DEP

    Why this is correct

    ROP is a technique that defeats DEP by chaining together short instruction sequences—called gadgets—that already exist in executable memory, such as in the C runtime library. Since DEP only prohibits execution from non-executable pages like the stack and heap, ROP never injects or executes new code on those pages; instead, it uses the CPU's ret instruction to jump between gadgets, building arbitrary behavior like calling VirtualProtect or system(). This makes it the correct approach when the stack is non-executable.

  • ✗

    Simple shellcode injection on the stack

    Why it's wrong here

    Simple shellcode injection on the stack is ineffective in this scenario because DEP marks the stack as non-executable (NX), so any payload placed there triggers an access violation when the CPU attempts to fetch an instruction from that page. Even if the buffer overflow precisely overwrites the return address, the injected machine code cannot run unless the stack has an executable permission bit cleared. This option also ignores other protections like stack canaries, but the fundamental failure is that the injected instructions cannot be executed under DEP.

  • ✗

    ASLR bypass techniques

    Why it's wrong here

    ASLR bypass techniques randomize the virtual address layout of libraries and stack, making it harder to locate ROP gadgets or locate injected code, but here ASLR is already disabled, so addresses are predictable. However, bypassing ASLR simply gives you predictable addresses for non-executable regions—it does nothing to lift the DEP restriction that prevents execution from the stack or heap. Thus, on its own, an ASLR bypass does not answer the challenge and cannot be the solution to bypass DEP.

  • ✗

    Heap spraying

    Why it's wrong here

    Heap spraying involves filling the heap with a large number of copies of shellcode, aiming to make the attacker's payload land at a predictable address despite ASLR. While this can defeat ASLR if the target heap address is known, it does not alter the NX (non-executable) attribute that DEP sets on the heap. Consequently, the sprayed shellcode is still not executable, and the overflow would fail to run any code, making heap spraying an incomplete answer for bypassing DEP.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.