Courseiva
hardMultiple Choice

PT0-002 Practice Question: During a penetration test, a tester identifies a…

During a penetration test, a tester identifies a buffer overflow vulnerability in a Linux binary. The system has ASLR and NX (Non-Executable) enabled. The tester finds a ROP gadget at a fixed address in a library that is loaded at a constant address across reboots. Which exploitation method is the most appropriate to achieve code execution?

⚠ Common exam trap

Test-takers frequently confuse return-to-libc with ROP, but return-to-libc is limited to calling a single function and cannot chain multiple gadgets, which is necessary for complex code execution when NX is enabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Return-Oriented Programming (ROP) chain

Return-Oriented Programming (ROP) is specifically designed to bypass both ASLR and NX when a fixed-address ROP gadget is available. Since the library is loaded at a constant address across reboots, the tester can chain gadgets from that library to execute arbitrary code without needing to inject executable shellcode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Return-to-libc attack

    Why it's wrong here

    Return-to-libc overwrites a saved return address to redirect execution directly to a libc function like system(), which works for a single call but fails when the exploit needs multiple sequential operations or complex argument setup. It also typically requires bypassing ASLR by leaking the libc base address; without that leak, the absolute address cannot be predicted. Because ROP generalizes this idea into an arbitrary chain, return-to-libc is a limited precursor, not a complete solution for a complex overflow.

  • ✓

    Return-Oriented Programming (ROP) chain

    Why this is correct

    ROP chains bypass both NX and, when gadget addresses are known (e.g., non-PIE binaries or after an info leak), ASLR by reusing short instruction sequences—gadgets—present in executable memory such as libc. The attacker controls the stack to chain gadgets that each end in a ret, allowing arbitrary operations like setting registers and calling functions without injecting shellcode. This makes ROP the most flexible and reliable code-reuse technique for a modern buffer overflow, far beyond a single function call.

  • ✗

    Heap spraying

    Why it's wrong here

    Heap spraying places many copies of shellcode throughout the heap to increase the chance that a corrupted pointer lands on one, but it does nothing to make the heap executable. Modern systems enforce NX on data segments, so sprayed shellcode would trigger an access violation if execution is redirected there. Even if a jump target is predictable, the attacker still needs to bypass NX, typically via a code-reuse technique like ROP, making heap spraying alone insufficient.

  • ✗

    SEH overwrite exploit

    Why it's wrong here

    SEH overwrite exploits are a Windows-specific technique that targets the structured exception handler chain to gain control when an exception is raised, often using pop-pop-ret sequences to pivot to attacker-controlled data. This attack is irrelevant in a Linux environment, which uses a different exception and signal model, so it cannot be the correct answer for a generic buffer overflow scenario. Even on Windows, modern protections like SafeSEH and ASLR complicate this technique without additional measures.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.