Courseiva

PEN-200 Buffer Overflow Fundamentals Practice Question

You are developing an exploit for a 32-bit Windows application that contains a stack-based buffer overflow. After overwriting EIP with a JMP ESP address, you place a payload that includes a reverse shell. During testing, the shell connects back successfully, but the application crashes immediately after the shell terminates. What is the most likely cause of the crash?

⚠ Common exam trap

The trap here is assuming that a successful shell connection means the exploit is flawless, overlooking that shellcode must terminate cleanly to avoid post-exploitation crashes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The shellcode lacks a proper exit sequence, causing the process to execute invalid memory after the shell ends.

The crash after the shell terminates suggests that the shellcode does not properly exit the process. When shellcode completes, it must call a termination function like ExitProcess; otherwise, the CPU continues executing whatever bytes follow, often leading to an access violation. The other options are inconsistent with the observed successful shell connection, which confirms that the overwrite and shellcode execution were correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The offset to EIP was miscalculated, causing the return address to be overwritten with an incorrect value.

    Why it's wrong here

    A miscalculated offset would typically prevent the JMP ESP from being executed, resulting in a crash before the shell connects. Because the reverse shell connects, the offset and EIP overwrite are correct. The crash after the shell exits indicates a different problem, such as missing exit code in the shellcode.

  • ✓

    The shellcode lacks a proper exit sequence, causing the process to execute invalid memory after the shell ends.

    Why this is correct

    When the shellcode finishes, it must exit cleanly; otherwise, execution continues into uninitialized or invalid memory, leading to a crash. Adding a call to ExitProcess or a similar termination routine ensures the process ends gracefully. This is a common issue when the shellcode is not designed to exit, especially if it spawns a shell and then returns to the overwritten return address or subsequent bytes.

  • ✗

    The shellcode was encoded with an XOR encoder that corrupted the payload after execution.

    Why it's wrong here

    An XOR encoder decodes the payload at runtime; if it were corrupting the payload, the shell likely would not execute at all. Since the reverse shell connects successfully, the encoding is functioning as intended. The crash occurs after the shell ends, pointing to a post-execution issue rather than encoding corruption.

  • ✗

    The JMP ESP address contains a null byte, which truncates the payload during transmission.

    Why it's wrong here

    Null bytes in the JMP ESP address would prevent the address from being written correctly in the first place, likely causing the EIP overwrite to fail entirely. However, in this scenario, the shell connects back, indicating the JMP ESP worked and the shellcode executed. Therefore, a null byte is not the cause of the post-shell crash.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.