Courseiva

PEN-200 Buffer Overflow Fundamentals Practice Question

During a buffer overflow exploit development, you need to determine the exact number of bytes required to overwrite the EIP register. Which method is most commonly used to find this offset?

⚠ Common exam trap

The trap here is thinking that sending a large number of 'A's is sufficient, but it only confirms a crash, not the exact offset needed for a reliable exploit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Generate a unique cyclic pattern, send it as input, and observe the value of EIP to calculate the offset.

The cyclic pattern method is the most efficient and precise way to find the EIP offset. By sending a unique pattern, the value in EIP after a crash directly indicates the offset when compared to the pattern. Other methods like sending 'A's or binary search are less precise or more labor-intensive. Debugger inspection can complement but is not the primary method for offset discovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform a binary search by sending payloads of varying lengths and checking if EIP is overwritten.

    Why it's wrong here

    A binary search can narrow down the offset, but it is time-consuming and requires many iterations. It also does not directly give the exact offset; you would still need to confirm the precise value. The cyclic pattern method is faster and provides the exact offset in a single crash, making it the preferred method.

  • ✗

    Send a series of 'A' characters in increasing lengths until the application crashes.

    Why it's wrong here

    Sending increasing lengths of 'A' can indicate that a crash occurs, but it does not provide the exact offset. All 'A' characters look the same, so when EIP is overwritten, it will contain 0x41414141, which does not reveal which specific bytes overwrote it. You would only know the approximate length, not the precise offset, making it inefficient and imprecise.

  • ✓

    Generate a unique cyclic pattern, send it as input, and observe the value of EIP to calculate the offset.

    Why this is correct

    A cyclic pattern, such as one generated by Metasploit's pattern_create, consists of a unique sequence of characters. When the application crashes, the value in EIP will be a subset of this pattern. By using pattern_offset with that value, you can determine the exact number of bytes from the start of the buffer to the return address. This is the standard and most reliable method for finding the offset.

  • ✗

    Use a debugger to set a breakpoint on the return instruction and inspect the stack pointer.

    Why it's wrong here

    Setting a breakpoint on the return instruction and inspecting the stack pointer can help identify where the return address is located, but it requires manual analysis and is not as straightforward as using a cyclic pattern. It may be useful in conjunction with other methods, but the cyclic pattern method is more direct and commonly used for finding the exact offset.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.