Courseiva

PEN-200 Buffer Overflow Fundamentals Practice Question

During exploitation of a stack-based buffer overflow on a 32-bit Windows application, you overwrite EIP with the address of a JMP ESP instruction, but the shellcode does not execute. You verify the JMP ESP address is correct and that the shellcode is in memory. Which of the following is the most likely cause?

⚠ Common exam trap

The trap here is overlooking the impact of null bytes in shellcode when using string copy functions, assuming that if the shellcode is in memory it must be intact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The shellcode contains null bytes, which terminate the string copy and prevent the full shellcode from being placed on the stack.

Null bytes in shellcode are a frequent problem when exploiting buffer overflows in string-based functions. Functions like strcpy or sprintf treat null bytes as string terminators, so any null byte in the shellcode will cause the copy to stop prematurely. As a result, the shellcode on the stack will be incomplete, and even with a correct JMP ESP, execution will fail. Therefore, ensuring shellcode is free of null bytes or properly encoded is essential. This is a common pitfall in Windows exploit development.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The JMP ESP instruction address contains a null byte, which prevents it from being written correctly to EIP.

    Why it's wrong here

    If the JMP ESP address contains a null byte, it might be truncated when written via a string function, but the scenario states that the JMP ESP address is correct and EIP is overwritten successfully. So this is not the issue. Null bytes in the address would be a problem during the overwrite, but since EIP is overwritten, it's not the cause here.

  • ✓

    The shellcode contains null bytes, which terminate the string copy and prevent the full shellcode from being placed on the stack.

    Why this is correct

    If the vulnerable function uses a string copy function like strcpy, null bytes in the shellcode will terminate the copy, truncating the shellcode. Even if the JMP ESP is correct, the shellcode on the stack may be incomplete, leading to failed execution. This is a common issue in Windows exploits, as many shellcodes contain null bytes. The scenario notes that shellcode is in memory, but it might be truncated. Thus, null bytes are a likely culprit.

  • ✗

    The shellcode is encoded, and the decoder stub is missing, so it cannot execute.

    Why it's wrong here

    If the shellcode is encoded without a decoder, it would not execute as intended, but the scenario says shellcode is in memory; it doesn't specify whether it's encoded. However, if encoded, it would typically include a decoder stub. The absence of a decoder would mean the encoded bytes are not valid instructions, but this is less likely than null byte truncation, which is a more common and specific issue in this context.

  • ✗

    The JMP ESP instruction is located in a memory region with the DEP (Data Execution Prevention) flag set.

    Why it's wrong here

    DEP prevents execution of code from data pages, but JMP ESP is an instruction in the code section, which is typically executable. DEP would not prevent the JMP itself; it would prevent shellcode execution if the shellcode is on the stack. However, the scenario states that the JMP ESP address is correct and shellcode is in memory; if DEP were blocking shellcode, the JMP would still occur, but then a DEP violation would crash the process. This is a possible cause, but not the most likely given the scenario details.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.