Courseiva

PEN-200 Buffer Overflow Fundamentals Practice Question

Which THREE of the following are essential steps when manually exploiting a stack-based buffer overflow?

⚠ Common exam trap

Candidates often skip the 'bad character' identification phase, which leads to shellcode truncation and exploit failure. They assume standard shellcode will work in every application environment without modification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identifying the crash offset by using a pattern generator.

Exploiting a buffer overflow requires a structured methodology to ensure the payload executes correctly. The process begins with identifying the crash and the exact offset to the return address. Once the offset is found, the investigator must locate a viable jump address and filter for bad characters that would break the payload. Finally, the shellcode is generated and tested to confirm that execution is successfully redirected to the desired payload.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identifying the crash offset by using a pattern generator.

    Why this is correct

    Using a unique cyclic pattern allows you to precisely determine the number of bytes required to overwrite the return address. This step is critical because any error in calculating the offset will cause the exploit to crash the program at the wrong location or fail to overwrite the target.

  • ✓

    Calculating the precise offset for the return address.

    Why this is correct

    Once the crash occurs using a cyclic pattern, identifying the exact bytes at the EIP allows you to know where the return address is situated. This precision is necessary to ensure the shellcode execution begins immediately after the function epilogue triggers the jump to your injected pointer.

  • ✗

    Disabling all firewall rules on the victim machine.

    Why it's wrong here

    Disabling firewall rules is not a step in buffer overflow exploitation. While you may need to ensure your shellcode can communicate back, the vulnerability exists within the application binary's memory handling. Security controls like firewalls are external to the local memory corruption process and do not affect the exploit.

  • ✓

    Identifying bad characters to prevent payload truncation.

    Why this is correct

    Testing for bad characters is essential because certain bytes can cause the application to stop reading the buffer prematurely. Finding these early ensures that your entire shellcode is successfully stored on the stack, which is the only way to ensure the CPU executes the intended instructions upon the jump.

  • ✗

    Upgrading the target application to the latest version.

    Why it's wrong here

    Upgrading the application would likely patch the vulnerability you are attempting to exploit. In a penetration test, you work with the vulnerable version provided. The goal is to identify and weaponize the existing flaw, not to make the application more secure through patching or standard maintenance procedures.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.