PEN-200 Buffer Overflow Fundamentals Practice Question
When fuzzing an application to identify a buffer overflow, what is the most common symptom indicating that the application's memory boundaries have been exceeded?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The application returns an 'Access Violation' or 'Segmentation Fault'
Fuzzing involves sending large amounts of data to an application to find stability issues. The most common indicator of a buffer overflow is the application crashing, specifically resulting in a segmentation fault or an access violation. This occurs because the injected data has overwritten critical stack memory, such as the return address, causing the CPU to attempt an execution from an invalid or unauthorized memory location.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application begins to consume high CPU resources
Why it's wrong here
High CPU utilization usually indicates an infinite loop or heavy processing. While possible, it is not a direct symptom of a memory corruption vulnerability like a buffer overflow. Buffer overflows typically manifest as immediate process crashes rather than sustained performance degradation or high compute intensity on the host machine.
- ✓
The application returns an 'Access Violation' or 'Segmentation Fault'
Why this is correct
When an overwrite corrupts the saved return address, the CPU eventually attempts to return to an address that is not valid or mapped, resulting in an immediate crash. This exception is the standard indicator for a successful fuzzer trigger, confirming the boundary has been exceeded and control is potentially lost.
- ✗
The application prints a stack dump to the console
Why it's wrong here
Modern applications rarely print stack dumps to the console unless specifically configured for debugging. Relying on this output is unreliable, as most production software suppresses such sensitive information. A crash or process termination is a much more reliable and universal sign that memory corruption has occurred during testing.
- ✗
The application generates a new network port listener
Why it's wrong here
A buffer overflow typically results in a crash, not the creation of new network services. If a new port appears, it is likely due to legitimate application functionality or a background process, not as a direct consequence of memory corruption caused by a fuzzing attempt against a standard buffer.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.