mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is attempting to exploit a…
A penetration tester is attempting to exploit a Linux system that has ASLR and DEP enabled. The tester has identified a buffer overflow vulnerability in a network service compiled without stack canaries and with a non-executable stack (NX). The binary is statically linked and not PIE. Which exploitation technique is most likely to succeed under these conditions?
⚠ Common exam trap
Test-takers frequently assume return-to-libc is always viable, forgetting that a statically linked binary has no libc to return to, making ROP the only way to call mprotect and bypass NX.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Return-Oriented Programming (ROP) to call mprotect and then execute shellcode on the stack
The binary is statically linked (no libc to return to) and has a non-executable stack (NX), so shellcode cannot execute directly on the stack. Return-Oriented Programming (ROP) allows the attacker to chain gadgets from the binary itself to call mprotect() and change the stack region to executable, then pivot to shellcode placed on the stack. Since ASLR is enabled but the binary is not PIE, its code base address is fixed, making ROP gadgets reliably addressable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Heap spraying to place shellcode in the heap and then overwrite a function pointer to execute the shellcode
Why it's wrong here
Heap spraying is often used when ASLR is present, but NX still prevents execution from the heap unless the heap is made executable. Also, the binary is not PIE, so addresses are known, but the heap may still be non-executable.
- ✗
Return-to-libc attack using libc functions
Why it's wrong here
Return-to-libc relies on calling a function such as system() from a dynamically linked C library at a known runtime address. Because the target binary is statically linked, there is no separately mapped libc library to 'return' to; the libc code is compiled directly into the executable. While the binary may contain system(), a classic ret2libc attack would require resolving libc's base address or using GOT/PLT entries, which are absent or unnecessary here. Instead, the attacker must assemble a ROP chain from gadgets within the binary's own .text segment to invoke mprotect and enable shellcode execution.
- ✓
Return-Oriented Programming (ROP) to call mprotect and then execute shellcode on the stack
Why this is correct
ROP allows the attacker to chain gadgets to call mprotect and change memory permissions on the stack to executable, then jump to shellcode placed on the stack. This bypasses NX while leveraging the known addresses from the statically linked, non-PIE binary.
- ✗
Ret2plt to call system() via the PLT
Why it's wrong here
Ret2plt is a technique that abuses the Procedure Linkage Table (PLT) and Global Offset Table (GOT) to dynamically resolve shared library functions at runtime. In a statically linked binary, all code, including libc functions, is compiled into the executable, so no PLT/GOT stubs exist to hijack. Even if system() is present, ret2plt cannot be applied because there are no lazy-binding stubs to redirect, and function addresses are fixed at compile time. This option is invalid in a static, non-PIE environment; the attacker must instead use direct ROP gadget chaining to change memory protections.
Go deeper
Related to this question
Learn chapter
Remote Code Execution (RCE) Vulnerabilities
Key term
Buffer overflow
A buffer overflow is a type of software vulnerability where a program writes more data to a memory buffer than it was designed to hold, causing adjacent memory to be overwritten.
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.