Courseiva
mediumMultiple Select

PT0-002 Practice Question: A penetration tester is examining a compiled…

A penetration tester is examining a compiled binary obtained during an engagement. The tester wants to identify potential buffer overflow vulnerabilities and understand the control flow. Which TWO tools would be most appropriate for this task?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OllyDbg

OllyDbg is a debugger that allows dynamic analysis to identify overflow vulnerabilities by examining memory and registers. Ghidra is a disassembler and decompiler that provides static analysis of control flow and potential vulnerabilities. Nmap is a network scanner, Wireshark is a packet analyzer, and Burp Suite is a web proxy, none of which are suitable for binary analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a network protocol analyzer that captures and dissects frames and packets traversing a network interface, focusing on headers, payloads, and protocol state at Layers 2-7. It never loads or executes the target binary, and it cannot inspect CPU registers, memory addresses, or disassembled instruction streams. For a compiled executable, its only marginal use would be observing the binary's outbound network traffic during a dynamic run, which is not a substitute for code-level analysis.

  • ✗

    Nmap

    Why it's wrong here

    Nmap is a network discovery and security auditing utility that sends crafted IP packets to identify live hosts, open TCP/UDP ports, OS fingerprints, and service versions. It treats the compiled binary as an opaque file, because it is neither a file parser nor a disassembler; it simply probes network endpoints. Thus Nmap can determine whether the binary acts as a network service, but it reveals nothing about vulnerable code paths, memory corruption, or the binary's logic.

  • ✓

    OllyDbg

    Why this is correct

    OllyDbg is a 32-bit user-mode debugger for Windows, well-known for assembling inline patches, analyzing stack imbalances, and stepping through instructions at the assembly level. It lets an analyst execute the binary dynamically, observe EIP/RSP moves, set conditional breakpoints on API calls like strcpy or memcpy, and manipulate memory to prove an overflow. This runtime perspective directly exposes how input affects control flow, making it the preferred tool for validating an exploit's viability within a live process.

  • ✗

    Burp Suite

    Why it's wrong here

    Burp Suite is an integrated platform for web application security testing, including intercepting proxies, repeaters, and scanners that manipulate HTTP/S requests between a browser and a backend server. It operates on TLS-terminated web traffic and parses JavaScript, not native machine code, and it has no support for loading portable executables or ELF files. Any vulnerability it finds (such as SQL injection or cross-site scripting) is a web-layer flaw, completely orthogonal to buffer overflows inside a compiled binary.

  • ✓

    Ghidra

    Why this is correct

    Ghidra is a reverse-engineering suite developed by the NSA that disassembles binaries into assembly and automatically decompiles them to a C-like pseudocode, enabling static analysis without execution. It constructs control-flow and data-flow graphs, resolves function boundaries, and allows cross-referencing of dangerous call sites (e.g., strcpy, gets) to map potential vulnerabilities. Ghidra's decompiler and headless scripting make it ideal for batch triage across a large set of binaries or for understanding an entire call chain before deciding where to place a dynamic debugger.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.