mediumMultiple Select
PT0-002 Practice Question: A penetration tester is examining a compiled…
A penetration tester is examining a compiled binary obtained during an engagement. The tester wants to identify potential buffer overflow vulnerabilities and understand the control flow. Which TWO tools would be most appropriate for this task?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OllyDbg
OllyDbg is a debugger that allows dynamic analysis to identify overflow vulnerabilities by examining memory and registers. Ghidra is a disassembler and decompiler that provides static analysis of control flow and potential vulnerabilities. Nmap is a network scanner, Wireshark is a packet analyzer, and Burp Suite is a web proxy, none of which are suitable for binary analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wireshark
Why it's wrong here
Wireshark is a network protocol analyzer that captures and dissects frames and packets traversing a network interface, focusing on headers, payloads, and protocol state at Layers 2-7. It never loads or executes the target binary, and it cannot inspect CPU registers, memory addresses, or disassembled instruction streams. For a compiled executable, its only marginal use would be observing the binary's outbound network traffic during a dynamic run, which is not a substitute for code-level analysis.
- ✗
Nmap
Why it's wrong here
Nmap is a network discovery and security auditing utility that sends crafted IP packets to identify live hosts, open TCP/UDP ports, OS fingerprints, and service versions. It treats the compiled binary as an opaque file, because it is neither a file parser nor a disassembler; it simply probes network endpoints. Thus Nmap can determine whether the binary acts as a network service, but it reveals nothing about vulnerable code paths, memory corruption, or the binary's logic.
- ✓
OllyDbg
Why this is correct
OllyDbg is a 32-bit user-mode debugger for Windows, well-known for assembling inline patches, analyzing stack imbalances, and stepping through instructions at the assembly level. It lets an analyst execute the binary dynamically, observe EIP/RSP moves, set conditional breakpoints on API calls like strcpy or memcpy, and manipulate memory to prove an overflow. This runtime perspective directly exposes how input affects control flow, making it the preferred tool for validating an exploit's viability within a live process.
- ✗
Burp Suite
Why it's wrong here
Burp Suite is an integrated platform for web application security testing, including intercepting proxies, repeaters, and scanners that manipulate HTTP/S requests between a browser and a backend server. It operates on TLS-terminated web traffic and parses JavaScript, not native machine code, and it has no support for loading portable executables or ELF files. Any vulnerability it finds (such as SQL injection or cross-site scripting) is a web-layer flaw, completely orthogonal to buffer overflows inside a compiled binary.
- ✓
Ghidra
Why this is correct
Ghidra is a reverse-engineering suite developed by the NSA that disassembles binaries into assembly and automatically decompiles them to a C-like pseudocode, enabling static analysis without execution. It constructs control-flow and data-flow graphs, resolves function boundaries, and allows cross-referencing of dangerous call sites (e.g., strcpy, gets) to map potential vulnerabilities. Ghidra's decompiler and headless scripting make it ideal for batch triage across a large set of binaries or for understanding an entire call chain before deciding where to place a dynamic debugger.
Go deeper
Related to this question
Learn chapter
Network Exploitation
Key term
Nmap
Nmap is a network scanning tool used to discover hosts, services, and operating systems on a computer network.
Key term
Buffer overflow
A buffer overflow is a type of software vulnerability where a program writes more data to a memory buffer than it was designed to hold, causing adjacent memory to be overwritten.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.