Courseiva

PEN-200 Buffer Overflow Fundamentals Practice Question

You are analyzing a Windows 32-bit application that uses a fixed-size stack buffer and calls strcpy() without bounds checking. You want to determine the exact offset to overwrite the saved return address. Which tool or method is most appropriate for this task?

⚠ Common exam trap

The trap here is thinking that static analysis or random fuzzing can pinpoint the offset, when dynamic pattern generation is needed to account for runtime stack layout.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a debugger to send a unique cyclic pattern and inspect the value of EIP.

The most reliable way to find the exact offset is to send a unique cyclic pattern and observe which four bytes overwrite EIP. This directly maps input position to the return address. Tools like Mona.py automate this process. Static counting or random fuzzing are less precise and can be misleading.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a disassembler to count the number of bytes between the buffer and the return address.

    Why it's wrong here

    Static analysis can give an estimate, but compiler optimizations, stack alignment, and local variables can change the actual offset. Dynamic analysis with a cyclic pattern is more reliable because it reflects the runtime behavior and exact overwrite point.

  • ✗

    Use a hex editor to modify the binary and insert a breakpoint at the return instruction.

    Why it's wrong here

    Modifying the binary is not required and does not help determine the offset. While breakpoints can help observe execution, you still need a method to correlate input bytes with the EIP value. Cyclic patterns are the standard method for offset discovery.

  • ✓

    Use a debugger to send a unique cyclic pattern and inspect the value of EIP.

    Why this is correct

    This is correct because sending a unique cyclic pattern allows you to identify the exact offset by observing the overwritten EIP value. Tools like Mona.py in Immunity Debugger or pattern_create/pattern_offset in Metasploit can generate and locate the offset. This is a standard step in buffer overflow exploitation.

  • ✗

    Use a fuzzer to send random data and monitor for a crash, then guess the offset.

    Why it's wrong here

    Fuzzing can trigger a crash, but it does not provide the exact offset. Random data may not follow a recognizable pattern, making it impossible to determine which bytes overwrite EIP. A systematic approach like cyclic patterns is necessary.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.