PEN-200 Buffer Overflow Fundamentals Practice Question
You have successfully found the exact offset to overwrite the EIP register and identified a reliable JMP ESP instruction inside an unProtected DLL. However, when your shellcode executes, the program immediately crashes with an access violation before launching the payload. Inspection reveals that the stack pointer (ESP) points directly to the beginning of your shellcode, but the memory page housing the stack lacks execution permissions. Which modern defense mechanism is preventing your exploit from succeeding?
⚠ Common exam trap
Candidates often blame bad shellcode or incorrect offsets when an exploit crashes on the stack, missing the fact that DEP prevents execution directly from stack memory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Execution Prevention (DEP) configured as OptOut or OptIn across the operating system environment.
Data Execution Prevention marks memory regions such as the stack and heap as non-executable to prevent malicious code from running directly from those locations. When an exploit attempts to jump into shellcode residing on the stack, the CPU generates an access violation because execution permissions are explicitly denied on that memory page.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Execution Prevention (DEP) configured as OptOut or OptIn across the operating system environment.
Why this is correct
Data Execution Prevention utilizes processor features to enforce non-executable memory pages, stopping shellcode placed directly on the stack from running. Bypassing this defense requires employing Return-Oriented Programming chains to alter memory protections or execute existing code blocks.
- ✗
Control Flow Guard (CFG) validating indirect call targets against a pre-compiled bitmap of valid function entries.
Why it's wrong here
Control Flow Guard secures indirect function calls by checking targets against a bitmap before execution proceeds. It does not prevent code execution on the stack unless an indirect call instruction is specifically involved in the transfer of control.
- ✗
Address Space Randomization relocating the base addresses of operating system libraries dynamically on every reboot.
Why it's wrong here
Address Space Layout Randomization randomizes memory locations to prevent attackers from reliably jumping to specific functions or gadgets. It does not restrict code execution permissions on specific memory regions like the stack on its own.
- ✗
Structured Exception Handling Overwrite Protection guarding exception handler chains from malicious pointer manipulation.
Why it's wrong here
Structured Exception Handling Overwrite Protection ensures that exception handlers cannot be overwritten or pointed to invalid memory locations during exploitation. It specifically targets SEH-based exploits rather than general stack-based shellcode execution failures.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.