Courseiva

GPEN Exploitation Fundamentals Practice Question

A penetration tester is preparing to exploit a stack-based buffer overflow on a Linux target. The target binary has non-executable stack (NX) enabled. Which technique should the tester use to achieve code execution?

⚠ Common exam trap

The trap here is assuming that classic stack shellcode injection still works when NX is enabled, overlooking the need to reuse existing code.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Return-to-libc (ret2libc) attack

Return-to-libc is the correct technique because it leverages existing executable code in shared libraries to bypass the non-executable stack. It allows the tester to call functions like `system()` to execute commands without injecting shellcode. Other options either assume an executable stack or are not applicable to stack-based overflows on Linux with NX enabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a NOP sled and jump to shellcode on the stack

    Why it's wrong here

    A NOP sled followed by shellcode on the stack requires the stack to be executable. With NX enabled, the CPU will prevent execution from the stack, causing a crash. This classic technique is ineffective against NX and would not lead to code execution in this scenario.

  • ✗

    Stack pivot to a writable and executable memory region

    Why it's wrong here

    Stack pivoting redirects execution to another memory area, but if NX is enabled, writable regions are typically non-executable. Without an executable region, pivoting alone does not bypass NX. This technique might be part of a larger exploit but does not directly solve the non-executable stack issue.

  • ✓

    Return-to-libc (ret2libc) attack

    Why this is correct

    Return-to-libc bypasses NX by reusing existing executable code in libc, such as `system()`, to execute commands. It does not require injecting shellcode onto the stack. This technique is effective when the stack is non-executable and is a standard method for exploiting buffer overflows in modern Linux environments with NX enabled.

  • ✗

    Heap spraying

    Why it's wrong here

    Heap spraying is used to place shellcode in predictable locations in memory, often for browser exploits. It does not bypass NX on the stack and is not applicable to a stack-based buffer overflow on a Linux binary. This technique is irrelevant to the scenario and would not achieve code execution.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.