Courseiva

PEN-200 Buffer Overflow Fundamentals Practice Question

You are developing an exploit for a Windows 32-bit application with a stack buffer overflow. You have identified a JMP ESP instruction at a static address. However, the application uses SafeSEH. Which statement is true regarding the use of JMP ESP in this scenario?

⚠ Common exam trap

The trap here is conflating SafeSEH with return address protection; SafeSEH only affects exception handler exploitation, not standard stack overflows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

JMP ESP can still be used if the address is in a module not compiled with SafeSEH.

SafeSEH is a mitigation for SEH overwrites, not for return address overwrites. If you are overwriting the saved return address, you can still use a JMP ESP gadget from a module that is not SafeSEH-protected. The presence of SafeSEH does not prevent this technique, as it only validates exception handlers when an exception occurs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SafeSEH encrypts the JMP ESP instruction, making it unusable.

    Why it's wrong here

    SafeSEH does not encrypt instructions. It maintains a table of valid exception handlers and checks them during exception handling. It has no effect on the JMP ESP instruction itself or its usability for return address overwrites.

  • ✗

    You must use a POP POP RET sequence instead of JMP ESP to bypass SafeSEH.

    Why it's wrong here

    POP POP RET is used to bypass SafeSEH when exploiting SEH overwrites, not return address overwrites. In a return address overwrite, you directly control EIP, so JMP ESP is appropriate. POP POP RET is irrelevant here unless you are targeting the SEH chain.

  • ✗

    JMP ESP will not work because SafeSEH validates all addresses on the stack, including the return address.

    Why it's wrong here

    SafeSEH validates exception handler addresses during exception dispatching, not the return address. The return address is used by the ret instruction, which is not checked by SafeSEH. Therefore, JMP ESP can still be effective if the module is not SafeSEH-protected.

  • ✓

    JMP ESP can still be used if the address is in a module not compiled with SafeSEH.

    Why this is correct

    This is correct because SafeSEH only protects exception handlers, not the return address overwrite. If you can overwrite the return address and redirect to a JMP ESP in a module without SafeSEH (or with SafeSEH disabled), you can still execute your shellcode. SafeSEH does not prevent stack overflow exploitation via return address overwrite.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.