PEN-200 Buffer Overflow Fundamentals Practice Question
Which of the following best describes the function of the EIP register in the context of a stack-based buffer overflow?
⚠ Common exam trap
Test-takers frequently confuse the EIP register with the ESP or the input buffer itself, failing to recognize that EIP specifically tracks the next instruction to be executed by the CPU.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It points to the memory address of the next instruction to be executed.
The EIP (Extended Instruction Pointer) register holds the memory address of the next instruction the CPU should execute. In an exploit, the goal is to overwrite this register by corrupting the saved return address on the stack. When the function finishes, the CPU pops this controlled value into EIP, forcing the processor to jump to the attacker's shellcode, thus hijacking the control flow of the entire application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It stores the current stack frame's base address.
Why it's wrong here
The EBP register stores the base address of the current stack frame, not the EIP. While EBP is important for stack frame management, it does not dictate the program execution flow in the same way that the instruction pointer does. The EIP is the primary target for flow hijacking exploits.
- ✓
It points to the memory address of the next instruction to be executed.
Why this is correct
EIP is the instruction pointer, which governs the flow of the program. By controlling this register, an attacker can redirect the CPU from its normal path of execution to any chosen memory address. This is the core mechanism that makes buffer overflow exploitation possible and effective for arbitrary code execution.
- ✗
It keeps track of the number of active threads.
Why it's wrong here
The EIP register has no role in thread management or tracking. Thread information is handled by the operating system kernel and the process environment block. EIP is dedicated solely to the execution flow of the current thread of execution at the hardware level, as defined by the x86 architecture.
- ✗
It holds the results of arithmetic operations.
Why it's wrong here
The EAX register is the primary accumulator for arithmetic operations. The EIP register is strictly reserved for the instruction pointer, as required by the CPU hardware to maintain program sequence. Using it for data storage would disrupt the program's ability to fetch and execute instructions correctly during normal operation.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.