PEN-200 Public Exploits Practice Question
You are reviewing a public exploit for a Linux-based web application. The exploit is a Python script that uses a hardcoded offset to overwrite a return address, and it includes a comment stating it was tested on a specific kernel version. Your target runs a different kernel but the same application version. After running the exploit, the service crashes but no shell is obtained. Which action is the MOST appropriate next step?
⚠ Common exam trap
The trap here is assuming a kernel mismatch makes the exploit unusable, when in fact it often just requires recalculating the offset after debugging the crash.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the exploit's offset to match the target's kernel by debugging the crash and calculating the correct offset.
A crash with no shell typically means the offset to the return address is wrong for the target's memory layout. Debugging the crash to find the correct offset and updating the exploit is the precise, minimal fix. This preserves the working parts of the exploit and directly addresses the kernel-dependent difference.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Recompile the target's kernel to match the version the exploit was tested on.
Why it's wrong here
You generally cannot recompile a remote target's kernel, and doing so would be an unrealistic and invasive action during an assessment. Even if you had local access, changing the kernel is far more disruptive than adjusting the exploit. The goal is to adapt the exploit to the target, not alter the target's core OS.
- ✓
Modify the exploit's offset to match the target's kernel by debugging the crash and calculating the correct offset.
Why this is correct
The crash indicates the exploit reached the vulnerable code but the return address was incorrect for this kernel. Debugging the crash (e.g., with a core dump or attaching a debugger) lets you determine the actual offset to the return address. Replacing the hardcoded offset with the correct one for the target kernel is the precise fix, rather than abandoning the exploit.
- ✗
Search for a different public exploit that targets the same application version but is written in a different language.
Why it's wrong here
The language of the exploit is irrelevant; the issue is the memory layout difference caused by the kernel version. Another script would likely have the same or different hardcoded offsets, but without understanding the target's layout you are guessing. The crash already confirms the vulnerability is reachable, so changing language does not address the root cause.
- ✗
Assume the exploit is unreliable and discard it, then attempt to exploit a different service on the target.
Why it's wrong here
The crash is a strong signal that the exploit works up to the point of control-flow hijack. Discarding it wastes a viable path. The kernel difference is a common and solvable problem; abandoning the exploit without investigating the offset is premature and may cause you to miss a direct route to compromise.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.