PEN-200 Buffer Overflow Fundamentals Practice Question
You have identified a stack-based buffer overflow in a Windows application. The application is compiled with SafeSEH, and you have confirmed that no SafeSEH-protected exception handlers can be overwritten. However, you notice that the stack is executable. You need to redirect execution to your shellcode. Which technique is most likely to succeed?
⚠ Common exam trap
The trap here is thinking that SafeSEH prevents all stack-based overflows; it only mitigates SEH overwrites, so return address overwrites remain viable if the stack is executable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Overwrite the saved return address with a pointer to a JMP ESP instruction in a non-ASLR module.
With an executable stack and SafeSEH in place, the most straightforward method is to overwrite the saved return address with a JMP ESP instruction from a module not protected by ASLR. This transfers control to the stack where the shellcode resides. SafeSEH is irrelevant because no exception handler is overwritten. This technique is a staple in OSCP-style buffer overflow exploitation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Overwrite the saved return address with a pointer to a JMP ESP instruction in a non-ASLR module.
Why this is correct
With an executable stack, placing shellcode on the stack and redirecting execution to it via a JMP ESP is a classic and reliable technique. The JMP ESP instruction jumps to the current stack pointer, which points to the shellcode if you have arranged the payload correctly. This bypasses SafeSEH because it does not rely on overwriting an exception handler.
- ✗
Overwrite the saved return address with the address of the shellcode on the stack.
Why it's wrong here
Directly jumping to a stack address is unreliable because stack addresses can vary between runs due to environment differences, debugger presence, or ASLR. Even if ASLR is not enabled, the exact stack address may not be stable. Using a JMP ESP instruction in a non-ASLR module provides a fixed indirection that reliably lands on the stack.
- ✗
Overwrite the SEH chain with a pointer to a POP POP RET sequence in a SafeSEH-compatible module.
Why it's wrong here
SafeSEH is specifically designed to prevent exploitation via SEH overwrites by validating that the exception handler address points to a registered handler. Even if you find a POP POP RET in a SafeSEH-compatible module, the handler address would not be registered, and the exception would not be dispatched. This technique is ineffective when SafeSEH is enforced.
- ✗
Use a return-to-libc attack by overwriting the return address with the address of the system() function.
Why it's wrong here
Return-to-libc is typically used when the stack is non-executable (NX/DEP enabled). In this scenario, the stack is executable, so the simpler and more direct JMP ESP technique is preferable. Additionally, return-to-libc requires crafting a fake stack frame with arguments, which may be complicated by stack layout and null bytes.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.