PEN-200 Buffer Overflow Fundamentals Practice Question
You are fuzzing a Linux x86-64 network service and cause a segmentation fault. You run the binary under GDB and see that the instruction pointer is 0x41414141. However, the crash address is in a non-executable stack region. Which technique should you use to redirect execution to your shellcode?
⚠ Common exam trap
The trap here is assuming that a larger buffer or a stack address can overcome NX, when in fact NX specifically prevents code execution from writable memory regions like the stack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a ret2libc attack to call system() with a pointer to "/bin/sh".
When the stack is non-executable, direct shellcode execution fails. The ret2libc technique bypasses this by reusing existing executable code, typically calling functions like system() with controlled arguments. This is a standard method taught in PEN-200 for defeating NX, provided you can locate the necessary addresses and gadgets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a heap spray to place shellcode in a predictable location and jump to it.
Why it's wrong here
Heap spraying is often used in browser exploits, but it does not bypass NX on the stack. The heap may also be non-executable, and the service may not allocate memory in a predictable manner. This approach is unreliable and not the standard solution for a non-executable stack.
- ✗
Overwrite the return address with a pointer to the stack and rely on the NX bit being disabled.
Why it's wrong here
The scenario states the stack is non-executable, so assuming NX is disabled is incorrect. Overwriting with a stack pointer will not work because the CPU will refuse to execute code from that region. This option ignores the fundamental protection in place.
- ✓
Use a ret2libc attack to call system() with a pointer to "/bin/sh".
Why this is correct
This is correct because the stack is non-executable, so you cannot execute shellcode directly on the stack. ret2libc leverages existing executable code in libc, such as system(), to spawn a shell. By controlling the return address and arguments, you can call system("/bin/sh") without needing executable stack permissions.
- ✗
Increase the size of the buffer to overwrite the saved return address with a stack address.
Why it's wrong here
Increasing the buffer size does not make the stack executable. Even if you overwrite the return address with a stack address, the NX bit prevents execution of code on the stack. This would still result in a crash when the CPU attempts to execute the shellcode.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.