Courseiva
Public Exploits →hardMultiple Choice

PEN-200 Public Exploits Practice Question

You are reviewing a public exploit for a Linux-based web application. The exploit script contains a function that constructs a payload using a format string vulnerability. Which of the following best describes the primary risk of using this exploit without modification on a target with a different libc version?

⚠ Common exam trap

The trap here is assuming that the format string offset is the main issue, when the more critical problem is the changing addresses of libc functions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The addresses of libc functions such as system() may differ, causing the exploit to jump to an invalid location.

When an exploit relies on hardcoded addresses of libc functions, those addresses are specific to the libc version used during development. On a target with a different libc, the addresses will differ, causing the exploit to fail or crash. This is a common pitfall when using public exploits across varied environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The exploit may trigger a stack canary check, which is not present in the original environment.

    Why it's wrong here

    Stack canaries are a compiler-level protection, not libc-dependent. If the target binary was compiled with stack canaries, the exploit would fail regardless of libc version. The scenario focuses on libc differences, so this is not the primary risk.

  • ✗

    The format string offset may differ, causing the exploit to write to an incorrect memory address.

    Why it's wrong here

    The format string offset is determined by the number of arguments before the format string on the stack. This offset is typically consistent across libc versions for the same binary and calling convention. While it can vary, it is not the primary risk when libc changes.

  • ✓

    The addresses of libc functions such as system() may differ, causing the exploit to jump to an invalid location.

    Why this is correct

    Different libc versions have different function addresses due to compilation and ASLR. If the exploit hardcodes addresses from one libc, it will fail on another. This is a common issue when using public exploits across systems with different libc versions.

  • ✗

    The format string vulnerability may be patched in the newer libc, rendering the exploit ineffective.

    Why it's wrong here

    The format string vulnerability is in the application, not libc. Libc provides the printf family functions, but the vulnerability arises from improper use in the application. Patching libc would not fix the application's misuse, so this is not the primary risk.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.