Courseiva

PEN-200 Buffer Overflow Fundamentals Practice Question

Which TWO of the following are common reasons for a buffer overflow exploit to fail even after the return address is correctly overwritten?

⚠ Common exam trap

Test-takers frequently assume that reaching EIP guarantees exploitation, overlooking environmental security mitigations like DEP or hidden bad characters that silently truncate payloads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The presence of undocumented bad characters in the payload.

Exploits often fail due to environmental factors that were not accounted for during the development phase. Even with a perfect offset, the presence of hidden bad characters can truncate the shellcode before it reaches the stack. Additionally, security controls like DEP (Data Execution Prevention) or ASLR (Address Space Layout Randomization) can prevent the shellcode from executing if the environment is locked down, rendering a simple stack-based overflow ineffective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The presence of undocumented bad characters in the payload.

    Why this is correct

    If a character is not identified as 'bad' during the initial testing phase, it can cause the input function to terminate the copy operation. This results in the shellcode being truncated, so the buffer contains only a partial payload that cannot perform the intended task when the CPU jumps to it.

  • ✗

    The use of a static JMP ESP address.

    Why it's wrong here

    Using a static JMP ESP address is the recommended best practice for reliable exploitation. It is a stable, constant redirection point. It would be highly unusual for this to cause an exploit to fail, as it is the most robust method for redirecting the instruction pointer to the stack reliably.

  • ✓

    The system has Data Execution Prevention (DEP) enabled.

    Why this is correct

    DEP marks the stack as non-executable. If DEP is active, even if you successfully redirect the instruction pointer to your shellcode on the stack, the CPU will refuse to execute those instructions and will immediately terminate the process. This security mechanism is a major hurdle for simple stack-based buffer overflows.

  • ✗

    The pattern generator failed to reach the buffer.

    Why it's wrong here

    If the pattern generator fails to reach the buffer, you would not be able to identify the offset to the return address. You would likely crash the program, but you wouldn't be able to achieve the specific control required for an exploit. This is a development failure, not an exploit failure.

  • ✗

    The shellcode is too short for the buffer.

    Why it's wrong here

    Having shellcode that is shorter than the buffer is actually fine, as you can simply fill the remaining space with NOPs or other filler data. The length of the shellcode is rarely a reason for failure, provided it is at least large enough to perform the required post-exploitation actions.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.