Courseiva

PEN-200 Buffer Overflow Fundamentals Practice Question

You are developing a proof-of-concept exploit for a Linux x86 UDP service that crashes when sent a long string of 'B's. Before attempting to redirect execution, you want to determine whether the crash gives you control of the instruction pointer. Which single action best confirms that the saved return address on the stack has been overwritten?

⚠ Common exam trap

The trap here is assuming that any crash after a long input proves EIP control, when only debugger inspection of the overwritten return address can confirm it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Send a unique, non-repeating pattern (e.g., generated by pattern_create) and inspect the value of EIP in the debugger after the crash.

Sending a unique cyclic pattern and inspecting EIP in a debugger is the definitive way to prove control of the instruction pointer and calculate the exact offset. The other actions only show that a crash or delivery occurred, which is insufficient to establish exploitability. This step precedes choosing a jump instruction or placing shellcode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use netcat to send 5000 'B's and observe that the service process terminates.

    Why it's wrong here

    A crash confirms the input reached a vulnerable code path, but it does not distinguish between a controlled overwrite and a simple denial of service. Without inspecting EIP contents, you cannot know whether the saved return address was overwritten or whether the crash came from an unrelated memory corruption. Debugger analysis is mandatory.

  • ✗

    Run the service under strace and check for a SIGSEGV signal in the output.

    Why it's wrong here

    strace reports system calls and signals, so it can show that a segmentation fault occurred, but it does not reveal the contents of CPU registers at the moment of the crash. A SIGSEGV alone does not prove EIP control; you need a debugger to see the overwritten return address and the exact value loaded into EIP.

  • ✓

    Send a unique, non-repeating pattern (e.g., generated by pattern_create) and inspect the value of EIP in the debugger after the crash.

    Why this is correct

    A cyclic pattern lets you map the exact bytes that land in EIP. When the service crashes, the value in EIP will be a recognizable slice of that pattern, proving you control the saved return address and revealing the precise offset. This is the standard first step in PEN-200 buffer overflow methodology before selecting a jump instruction or encoding shellcode.

  • ✗

    Attach a packet sniffer to the loopback interface and look for the string '41414141' in the UDP payload.

    Why it's wrong here

    Sniffing the wire only shows what you sent, not how the application processed it. Seeing your own payload confirms delivery but says nothing about whether the return address was overwritten or whether EIP is controllable. Debugger inspection after the crash is required to observe register state and confirm control of execution flow.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.