PEN-200 Buffer Overflow Fundamentals Practice Question
When analyzing a stack buffer, what is the significance of the 'saved EBP' value?
⚠ Common exam trap
Many candidates confuse the saved EBP with the instruction pointer, mistakenly believing that overwriting EBP directly alters the execution flow rather than crashing during the function epilogue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It helps the program restore the previous stack frame.
The saved EBP is part of the standard function epilogue, which helps the program restore the stack frame of the calling function. In a buffer overflow, this value is overwritten immediately before the return address. While usually not the primary target for flow hijacking, it is a critical piece of the stack frame that, if corrupted, will likely cause the program to crash when it attempts to restore the stack frame after the function finishes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It is the primary register for shellcode execution.
Why it's wrong here
The EBP register is not used for shellcode execution. EIP is the register responsible for execution flow. EBP is simply used for stack frame management. Using EBP to point to shellcode would not work, as the CPU does not fetch instructions from the EBP register during the function return sequence.
- ✓
It helps the program restore the previous stack frame.
Why this is correct
The saved EBP is used by the function epilogue (specifically the LEAVE or POP EBP instructions) to restore the stack pointer to the state of the calling function. Overwriting this value is necessary to reach the return address, but it often leads to a crash if the stack cannot be properly unwound.
- ✗
It is a security mechanism to prevent overflows.
Why it's wrong here
The saved EBP is a byproduct of the standard x86 function calling convention, not a security feature. It is not designed to prevent overflows, detect corruption, or provide any protection against malicious input. It is simply a structural requirement of how functions manage memory on the stack in modern CPU architectures.
- ✗
It stores the base address of the shellcode.
Why it's wrong here
The saved EBP has no relationship to the shellcode or its location. Its value is determined by the caller's stack frame. It does not contain any information about where the shellcode is stored. Any relationship between EBP and the shellcode would be purely coincidental and not a standard feature of the stack.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.