PEN-200 Buffer Overflow Fundamentals Practice Question
Exhibit
Refer to the exhibit: [ESP address: 0x0012FF70] [EIP value: 0x41414141] [JMP ESP address: 0x77E14C29]
Given the exhibit, what is the correct strategy to redirect control flow to the shellcode?
⚠ Common exam trap
Candidates often try to jump directly to a hardcoded address on the stack, which is unreliable. They forget that the stack address changes across different environments and executions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Overwrite the EIP value with the address 0x77E14C29.
To redirect execution, you must replace the EIP value (currently 0x41414141) with the memory address of a JMP ESP instruction. The JMP ESP instruction serves as a pivot point that redirects the CPU to the stack, where your shellcode is located. By placing the address 0x77E14C29 in the exact offset where EIP is overwritten, the CPU will execute the jump instead of attempting to return to the original, now-corrupted address.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Replace the EIP value with 0x0012FF70.
Why it's wrong here
The ESP address changes frequently and is not a reliable destination for the return address. Using the address of the stack directly is highly unstable and will likely fail as the stack pointer shifts. You must use a static JMP ESP address to reliably redirect the flow to the stack.
- ✓
Overwrite the EIP value with the address 0x77E14C29.
Why this is correct
Replacing the EIP value with the static JMP ESP address ensures that when the function returns, the CPU immediately executes the jump instruction. This instruction points the CPU to the current location of the stack pointer, effectively directing the execution flow to the shellcode payload injected by the user.
- ✗
Nop out the EIP value with 0x90909090.
Why it's wrong here
The EIP register expects a valid memory address. If you set it to 0x90909090, the CPU will attempt to fetch instructions from that address, which is not executable. This will cause an immediate crash rather than redirecting the execution flow to your shellcode, failing the exploit attempt entirely.
- ✗
Force the program to jump to the base address 0x00400000.
Why it's wrong here
Jumping to the base address of the application is arbitrary and will not lead to your shellcode. The shellcode is located on the stack, not in the program's code segment. This jump would likely result in an attempt to execute non-existent or data-only code, causing a crash.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.