Courseiva

PEN-200 Buffer Overflow Fundamentals Practice Question

You have identified a stack-based buffer overflow in a Windows application. The application is compiled with SafeSEH, and you have confirmed that no SafeSEH-protected exception handlers can be overwritten. However, you notice that the stack is executable. You need to redirect execution to your shellcode. Which technique is most likely to succeed?

⚠ Common exam trap

The trap here is thinking that SafeSEH prevents all stack-based overflows; it only mitigates SEH overwrites, so return address overwrites remain viable if the stack is executable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Overwrite the saved return address with a pointer to a JMP ESP instruction in a non-ASLR module.

With an executable stack and SafeSEH in place, the most straightforward method is to overwrite the saved return address with a JMP ESP instruction from a module not protected by ASLR. This transfers control to the stack where the shellcode resides. SafeSEH is irrelevant because no exception handler is overwritten. This technique is a staple in OSCP-style buffer overflow exploitation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Overwrite the saved return address with a pointer to a JMP ESP instruction in a non-ASLR module.

    Why this is correct

    With an executable stack, placing shellcode on the stack and redirecting execution to it via a JMP ESP is a classic and reliable technique. The JMP ESP instruction jumps to the current stack pointer, which points to the shellcode if you have arranged the payload correctly. This bypasses SafeSEH because it does not rely on overwriting an exception handler.

  • ✗

    Overwrite the saved return address with the address of the shellcode on the stack.

    Why it's wrong here

    Directly jumping to a stack address is unreliable because stack addresses can vary between runs due to environment differences, debugger presence, or ASLR. Even if ASLR is not enabled, the exact stack address may not be stable. Using a JMP ESP instruction in a non-ASLR module provides a fixed indirection that reliably lands on the stack.

  • ✗

    Overwrite the SEH chain with a pointer to a POP POP RET sequence in a SafeSEH-compatible module.

    Why it's wrong here

    SafeSEH is specifically designed to prevent exploitation via SEH overwrites by validating that the exception handler address points to a registered handler. Even if you find a POP POP RET in a SafeSEH-compatible module, the handler address would not be registered, and the exception would not be dispatched. This technique is ineffective when SafeSEH is enforced.

  • ✗

    Use a return-to-libc attack by overwriting the return address with the address of the system() function.

    Why it's wrong here

    Return-to-libc is typically used when the stack is non-executable (NX/DEP enabled). In this scenario, the stack is executable, so the simpler and more direct JMP ESP technique is preferable. Additionally, return-to-libc requires crafting a fake stack frame with arguments, which may be complicated by stack layout and null bytes.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.