
EC-CouncilCertified Penetration Testing Professional
Domain 6Objective 1
Reverse Engineering, Fuzzing, and Binary Exploitation CPENT Practice Questions (Page 2)
Part of the Advanced Exploitation and IoT domain, which makes up ~17% of our current practice bank.
59questions here
12free pages
16concepts
Questions 6–10
- 6
A fuzzing campaign on a network service produces hundreds of crashes. The tester wants to prioritize which crashes to analyze first for potential exploitability. Which approach is most appropriate?
Select an answer first - 7
A security team wants to fuzz a command-line tool that parses configuration files. The tool is open-source and can be compiled with instrumentation. The team wants to maximize code coverage and find crashes efficiently. Which fuzzing framework is most appropriate?
Select an answer first - 8
A penetration tester is exploiting a buffer overflow in a Linux binary that has ASLR and stack canaries enabled. The tester has found a way to leak a canary value and a libc address. Which mitigation bypass technique is most appropriate?
Select an answer first - 9
A fuzzing campaign on a network daemon has produced a crash. The crash report shows a SIGSEGV in a function that processes a linked list. The tester suspects a use-after-free vulnerability. Which analysis step is most critical to confirm this hypothesis and distinguish it from a simple NULL pointer dereference?
Select an answer first - 10
A penetration tester is assessing an IoT device that runs an ARM-based firmware. The device has a web interface that is vulnerable to a buffer overflow in the HTTP header parsing. The firmware is protected by NX and ASLR, and the tester cannot easily obtain a libc leak. The device has a small memory footprint and no standard libc functions are directly reachable. Which exploitation strategy is most likely to succeed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.