Courseiva

PEN-200 Buffer Overflow Fundamentals Practice Question

During a buffer overflow exploit development, you need to ensure that your shellcode does not contain any null bytes. You have generated shellcode that includes a null byte. Which of the following is the most appropriate action?

⚠ Common exam trap

The trap here is assuming that any null-free shellcode will work without considering that the encoder must also preserve the shellcode's functionality and be compatible with the available space.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an encoder such as Shikata Ga Nai to encode the shellcode, which will remove null bytes and add a decoder stub.

When shellcode contains bad characters like null bytes, encoding it with a tool like Shikata Ga Nai is the standard solution. The encoder transforms the shellcode into a null-free version and adds a decoder stub that reconstructs the original code in memory. This allows the exploit to deliver the payload without the bad characters causing premature termination. It is a fundamental step in exploit development, especially for stack-based overflows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Manually replace the null byte with a NOP (0x90) instruction.

    Why it's wrong here

    Replacing a null byte with a NOP changes the instruction stream and will likely break the shellcode's functionality. Null bytes are often part of immediate values or addresses, and substituting them alters the code's behavior. This approach is not viable for producing working shellcode; it would cause the exploit to fail or crash.

  • ✓

    Use an encoder such as Shikata Ga Nai to encode the shellcode, which will remove null bytes and add a decoder stub.

    Why this is correct

    Encoders like Shikata Ga Nai are designed to transform shellcode to avoid bad characters such as null bytes. They prepend a decoder stub that reconstructs the original shellcode at runtime. This is a standard technique in exploit development when bad characters are present. The encoded shellcode is larger but functionally equivalent after decoding.

  • ✗

    Split the shellcode into two parts and execute them sequentially using a staged payload.

    Why it's wrong here

    Splitting shellcode into stages is used to bypass size restrictions, not to remove bad characters. A stager typically downloads the second stage, which may still contain null bytes. This does not address the null byte issue directly. Moreover, implementing a staged payload adds complexity and may not be necessary if encoding can solve the problem.

  • ✗

    Use a different shellcode that does not contain null bytes, such as one generated with the 'alpha_mixed' encoder.

    Why it's wrong here

    While using null-free shellcode is ideal, the 'alpha_mixed' encoder is not a shellcode generator but an encoder that produces alphanumeric output. It may still contain null bytes? Actually, alpha_mixed produces alphanumeric characters, which exclude null bytes. However, the question states you have shellcode with a null byte; the most appropriate action is to encode it. Simply switching to another shellcode may not be possible if the desired payload is only available with null bytes. Encoding is the general solution.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.