Courseiva

PEN-200 · topic practice

Buffer Overflow Fundamentals practice questions

This domain covers stack-based buffer overflow exploitation on 32-bit targets, as taught in PEN-200 and exercised in the OSCP lab and exam. You must recognize a crash, control EIP, find bad characters, locate a JMP ESP or equivalent return address, generate shellcode with msfvenom, and land a working reverse or bind shell on the target.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Buffer Overflow Fundamentals

What the exam tests

What to know about Buffer Overflow Fundamentals

You must be able to take a crashing 32-bit service, compute the EIP offset, filter bad characters, find a JMP ESP address, and deliver msfvenom shellcode that returns a shell. The single most important thing is verifying EIP control and bad characters before finalizing the payload.

Using a fuzzer or pattern_create/pattern_offset to find the exact EIP overwrite offset

Identifying bad characters by sending byte arrays and inspecting the debugger memory dump

Locating a JMP ESP or CALL ESP instruction with mona.py or Immunity Debugger

Generating and delivering msfvenom shellcode that spawns a reverse or bind shell

Watch out for

Common Buffer Overflow Fundamentals exam traps

  • ▸Assuming the offset from pattern_offset is correct without re-verifying EIP control with a unique four-byte value such as BBBB
  • ▸Forgetting that null bytes and other bad characters will truncate shellcode, causing the payload to fail silently after EIP control
  • ▸Placing shellcode before the saved return address when the buffer is too small, instead using a jump back into the buffer or a larger buffer region

Practice set

Buffer Overflow Fundamentals questions

20 questions · select your answer, then reveal the explanation

In the context of the PEN-200, why is the 'JMP ESP' instruction considered the 'gold standard' for stack-based overflows?

You are developing an exploit for a 32-bit Windows application. After sending a 5000-byte payload, you observe that the EIP value is 0x41414141. However, your payload contains no 'A' characters after byte 2000. What is the most likely reason for this EIP value?

You are exploiting a stack-based buffer overflow on a Linux x86-64 binary. You have determined the offset to overwrite the return address. Which TWO of the following steps are essential to achieve reliable code execution? (Choose two.)

You are preparing to exploit a stack-based buffer overflow in a 32-bit Windows application. You have identified the offset to EIP and found a reliable JMP ESP instruction. Which TWO of the following steps are essential to ensure the shellcode executes successfully? (Choose two.)

You are exploiting a stack-based buffer overflow in a Linux x86 binary. The binary has NX enabled, but you have identified a way to leak a stack address. You plan to use a return-to-libc attack to call system("/bin/sh"). Which TWO of the following are required to successfully execute this attack? (Choose two.)

You are analyzing a 32-bit Windows executable and notice that the stack is executable. You want to place your shellcode directly on the stack and redirect execution to it. Which of the following is the most reliable way to redirect execution to your shellcode?

You are preparing to exploit a stack-based buffer overflow in a 32-bit Linux binary running as a setuid root program. The binary is compiled without stack canaries and has no ASLR. You have confirmed EIP control and identified a suitable JMP ESP equivalent. Which TWO of the following steps are necessary to ensure reliable shellcode execution after overwriting the return address? (Choose two.)

You are analyzing a 32-bit Windows application that crashes when a long string is sent to a network service. The crash occurs in a function that copies data into a 256-byte stack buffer using a loop that stops at a null byte. You have determined that the offset to EIP is 260 bytes. However, when you send a payload with 260 'A's followed by a JMP ESP address and shellcode, the application crashes but no shellcode executes. What is the most likely explanation?

You are analyzing a binary and identify a function that uses strcpy() to copy user input into a fixed-size stack buffer. Which register must be controlled to redirect the instruction pointer to your shellcode?

Based on the exhibit, what is the primary risk if your shellcode contains the byte \x0d?

Exhibit

Refer to the exhibit: [ 0x00401000 - 0x00401050 ] Bad Characters: \x00, \x0a, \x0d. Shellcode Offset: 140 bytes. Target Jump: JMP ESP (0x62501205).

Which TWO of the following statements correctly describe the function of a NOP sled in a buffer overflow exploit?

When fuzzing an application to identify a buffer overflow, what is the most common symptom indicating that the application's memory boundaries have been exceeded?

Why must you carefully identify 'bad characters' before finalizing an exploit payload?

Which THREE of the following are essential steps when manually exploiting a stack-based buffer overflow?

Given the exhibit, what is the correct strategy to redirect control flow to the shellcode?

Exhibit

Refer to the exhibit: [ESP address: 0x0012FF70] [EIP value: 0x41414141] [JMP ESP address: 0x77E14C29]

Which of the following best describes the function of the EIP register in the context of a stack-based buffer overflow?

Why are static memory addresses for 'JMP ESP' preferred over dynamic stack addresses?

What role does the 'padding' play in a buffer overflow payload structure?

Given the exhibit, why might using the address 0x00401020 to overwrite EIP be ineffective for shellcode execution?

Exhibit

Refer to the exhibit: [ESP: 0x0012FF70] [EIP: 0x00401020] [Instruction: 0x00401020 - CALL [EAX]]

What is the primary purpose of an exploit payload in a buffer overflow context?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Buffer Overflow Fundamentals sessions

Start a Buffer Overflow Fundamentals only practice session

Every question in these sessions is drawn from the Buffer Overflow Fundamentals domain — nothing else.

Related practice questions

Related PEN-200 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PEN-200 exam test about Buffer Overflow Fundamentals?
You must be able to take a crashing 32-bit service, compute the EIP offset, filter bad characters, find a JMP ESP address, and deliver msfvenom shellcode that returns a shell. The single most important thing is verifying EIP control and bad characters before finalizing the payload.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Buffer Overflow Fundamentals questions in a focused session?
Yes — the session launcher on this page draws every question from the Buffer Overflow Fundamentals domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PEN-200 topics?
Use the topic links above to move to related areas, or go back to the PEN-200 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PEN-200 exam covers. They are not copied from any real exam or dump site.