Courseiva

GPEN Exploitation Fundamentals Practice Question

When planning an exploit that requires a specific memory address, which THREE techniques can a tester use to increase the reliability of the exploit?

⚠ Common exam trap

Candidates often select incorrect options like static DLL injection or standard brute forcing, failing to recognize that NOP sleds, heap spraying, and ROP gadgets directly address memory unpredictability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Heap spraying to fill memory with the payload.

Memory reliability is the primary hurdle in binary exploitation. Techniques like heap spraying, NOP sleds, and ROP gadgets are designed to circumvent the uncertainty of memory addresses. By using these methods, a tester creates a more robust exploit that does not rely on perfect, single-point accuracy, which is almost impossible to achieve in modern systems with complex memory management and various active security mitigations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Heap spraying to fill memory with the payload.

    Why this is correct

    Heap spraying involves allocating many large chunks of memory containing the shellcode. This increases the probability that the instruction pointer will land on the payload, even if the exact destination address is unknown. It is a powerful technique for overcoming the unpredictability of randomized memory allocation.

  • ✓

    Using a large NOP sled before the shellcode.

    Why this is correct

    A NOP sled provides a wide landing zone for the instruction pointer. By increasing the size of this sled, the tester significantly improves the chances that the exploit will redirect execution into the shellcode, even if the jump target is slightly off the intended memory address location.

  • ✗

    Disabling the target's operating system logging.

    Why it's wrong here

    Disabling logging is a stealth technique to prevent detection. It does not help with the reliability of an exploit or the predictability of memory addresses. Memory management is handled by the CPU and the kernel; logging settings have no impact on where code is executed in memory.

  • ✓

    Employing ROP gadgets to bypass ASLR/DEP.

    Why this is correct

    ROP chains allow the tester to execute code using existing, executable memory fragments. Since these fragments are part of the original application, they are already present and mapped, bypassing the need to guess the exact location of injected shellcode and effectively rendering ASLR/DEP protections much less effective.

  • ✗

    Increasing the network MTU size.

    Why it's wrong here

    MTU size relates to network packet fragmentation and transmission efficiency. It has no relevance to memory-based exploitation or the reliability of code execution within a target process. Adjusting network settings will not change how memory is allocated or accessed by the target's internal software processes.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.