Courseiva

PEN-200 Buffer Overflow Fundamentals Practice Question

Which of the following best describes the function of the EIP register in the context of a stack-based buffer overflow?

⚠ Common exam trap

Test-takers frequently confuse the EIP register with the ESP or the input buffer itself, failing to recognize that EIP specifically tracks the next instruction to be executed by the CPU.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It points to the memory address of the next instruction to be executed.

The EIP (Extended Instruction Pointer) register holds the memory address of the next instruction the CPU should execute. In an exploit, the goal is to overwrite this register by corrupting the saved return address on the stack. When the function finishes, the CPU pops this controlled value into EIP, forcing the processor to jump to the attacker's shellcode, thus hijacking the control flow of the entire application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It stores the current stack frame's base address.

    Why it's wrong here

    The EBP register stores the base address of the current stack frame, not the EIP. While EBP is important for stack frame management, it does not dictate the program execution flow in the same way that the instruction pointer does. The EIP is the primary target for flow hijacking exploits.

  • ✓

    It points to the memory address of the next instruction to be executed.

    Why this is correct

    EIP is the instruction pointer, which governs the flow of the program. By controlling this register, an attacker can redirect the CPU from its normal path of execution to any chosen memory address. This is the core mechanism that makes buffer overflow exploitation possible and effective for arbitrary code execution.

  • ✗

    It keeps track of the number of active threads.

    Why it's wrong here

    The EIP register has no role in thread management or tracking. Thread information is handled by the operating system kernel and the process environment block. EIP is dedicated solely to the execution flow of the current thread of execution at the hardware level, as defined by the x86 architecture.

  • ✗

    It holds the results of arithmetic operations.

    Why it's wrong here

    The EAX register is the primary accumulator for arithmetic operations. The EIP register is strictly reserved for the instruction pointer, as required by the CPU hardware to maintain program sequence. Using it for data storage would disrupt the program's ability to fetch and execute instructions correctly during normal operation.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.