Courseiva
Public Exploits →mediumMultiple Choice

PEN-200 Public Exploits Practice Question

During a PEN-200 lab exercise, you find a public exploit for a Windows service. The exploit source contains a hardcoded return address of 0x41414141 and a comment that it was tested against a different Windows build with ASLR disabled. What should you do before running it against your target?

⚠ Common exam trap

The trap here is assuming a public exploit will work unchanged against any Windows build, ignoring the fact that return addresses and ASLR settings are build-specific.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Recompile the exploit with a debugger, identify the correct return address for this target, and update the payload accordingly.

A public exploit with a hardcoded return address and a note about ASLR being disabled on a different build is not portable as-is. The reliable path is to debug the target process, calculate the correct offset and return address for the specific Windows build, and update the exploit's payload. Blindly running it risks a crash, and altering the target's ASLR configuration is neither appropriate nor feasible without prior access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run the exploit as-is and observe the target's behavior to determine whether ASLR is enabled.

    Why it's wrong here

    Running the exploit unchanged against a target with ASLR enabled will likely crash the vulnerable service without achieving code execution, potentially destabilizing the host and losing your foothold. The hardcoded 0x41414141 return address and comment about a different build with ASLR disabled are red flags that the exploit is not reliable here. Observation should come from configuration checks, not from a blind execution attempt.

  • ✗

    Replace the hardcoded return address with a NOP sled of equivalent length and rerun the exploit.

    Why it's wrong here

    A NOP sled does not replace a return address; it is a sequence of no-operation instructions that helps the CPU slide into shellcode. Substituting a NOP sled for the return address would cause the exploit to jump to an unpredictable location and likely crash the service. The return address must point to a valid instruction that transfers control to the payload.

  • ✓

    Recompile the exploit with a debugger, identify the correct return address for this target, and update the payload accordingly.

    Why this is correct

    The hardcoded address and the note about ASLR being disabled on a different build indicate the exploit must be retargeted. By attaching a debugger such as Immunity Debugger or WinDbg, determining the actual return address and offset for your specific Windows build, and updating the payload, you adapt the exploit to the target's memory layout. This is the standard PEN-200 approach for porting public exploits.

  • ✗

    Disable ASLR on the target by editing the system registry, then run the exploit unchanged.

    Why it's wrong here

    Modifying the target's registry to disable ASLR is a post-exploitation or test-environment action, not something you would do during an initial exploitation attempt. It also requires administrative access you do not yet have, and it changes the target's security posture in a way that may violate the engagement scope. The correct approach is to adapt the exploit, not alter the target's defenses.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.