Courseiva
mediumMultiple Choice

PT0-002 Practice Question: During a network penetration test, the tester…

During a network penetration test, the tester identifies that a web server is vulnerable to a buffer overflow. The server is running on a Windows system with DEP enabled. Which technique should the tester use to bypass DEP?

⚠ Common exam trap

Many candidates confuse DEP bypass with simple shellcode injection (Option C) or assume stack pivoting alone bypasses DEP, when in fact ROP is the standard technique to execute code without relying on executable stack memory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Return-Oriented Programming (ROP)

Return-Oriented Programming (ROP) is the correct technique to bypass Data Execution Prevention (DEP) on Windows. DEP marks memory pages (like the stack and heap) as non-executable, preventing direct shellcode execution. ROP chains together small instruction sequences (gadgets) already present in executable memory (e.g., in loaded DLLs) to achieve arbitrary behavior without injecting or executing new code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Return-to-libc attack

    Why it's wrong here

    Return-to-libc bypasses NX on Linux by redirecting control flow to an existing libc function, but on Windows with DEP it is less straightforward. Windows binaries are often compiled with /GS, ASLR, and the simple system() call pattern is complicated by address null bytes and the need for multiple API calls. ROP is the more common DEP bypass because it chains many small existing code sequences, rather than directly invoking a single function.

  • ✓

    Return-Oriented Programming (ROP)

    Why this is correct

    Return-Oriented Programming (ROP) defeats DEP because it never places or executes new code in non-executable data pages. Instead, the attacker overwrites the return address chain on the stack to sequentially invoke existing instructions, known as gadgets, each ending with a `ret` instruction. By carefully selecting and chaining gadgets, the attacker can perform arbitrary computations and call APIs, all within executable memory regions, thus evading DEP's instruction execution blocking.

  • ✗

    Use a NOP sled and shellcode injection

    Why it's wrong here

    A NOP sled combined with shellcode injection typically targets a stack-based buffer overflow by spraying a large slide of NOP instructions and then jumping into the middle of it to execute injected shellcode. With DEP enabled, the stack and heap pages are marked non-executable, so any attempt to execute the NOP sled or shellcode triggers a hardware exception and terminates the process. This classic technique fails because it relies on executing code from data memory, which DEP explicitly prohibits.

  • ✗

    Stack pivoting

    Why it's wrong here

    Stack pivoting is an exploitation technique that changes the stack pointer (e.g., via a `pop esp; ret` gadget) to point to a controlled buffer, such as one on the heap. It is commonly used to relocate the ROP chain when the original stack region is too small or its address is unpredictable. However, pivoting alone does not bypass DEP, as the new pivot target is also a non-executable data page; it only provides a stable stack for a subsequent ROP chain.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.