GPEN Exploitation Fundamentals Practice Question
A penetration tester is preparing to exploit a stack-based buffer overflow on a Linux target. The target binary has non-executable stack (NX) enabled. Which technique should the tester use to achieve code execution?
⚠ Common exam trap
The trap here is assuming that classic stack shellcode injection still works when NX is enabled, overlooking the need to reuse existing code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Return-to-libc (ret2libc) attack
Return-to-libc is the correct technique because it leverages existing executable code in shared libraries to bypass the non-executable stack. It allows the tester to call functions like `system()` to execute commands without injecting shellcode. Other options either assume an executable stack or are not applicable to stack-based overflows on Linux with NX enabled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a NOP sled and jump to shellcode on the stack
Why it's wrong here
A NOP sled followed by shellcode on the stack requires the stack to be executable. With NX enabled, the CPU will prevent execution from the stack, causing a crash. This classic technique is ineffective against NX and would not lead to code execution in this scenario.
- ✗
Stack pivot to a writable and executable memory region
Why it's wrong here
Stack pivoting redirects execution to another memory area, but if NX is enabled, writable regions are typically non-executable. Without an executable region, pivoting alone does not bypass NX. This technique might be part of a larger exploit but does not directly solve the non-executable stack issue.
- ✓
Return-to-libc (ret2libc) attack
Why this is correct
Return-to-libc bypasses NX by reusing existing executable code in libc, such as `system()`, to execute commands. It does not require injecting shellcode onto the stack. This technique is effective when the stack is non-executable and is a standard method for exploiting buffer overflows in modern Linux environments with NX enabled.
- ✗
Heap spraying
Why it's wrong here
Heap spraying is used to place shellcode in predictable locations in memory, often for browser exploits. It does not bypass NX on the stack and is not applicable to a stack-based buffer overflow on a Linux binary. This technique is irrelevant to the scenario and would not achieve code execution.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.