
EC-CouncilCertified Penetration Testing Professional
Domain 6Objective 1
Reverse Engineering, Fuzzing, and Binary Exploitation CPENT Practice Questions (Page 7)
Part of the Advanced Exploitation and IoT domain, which makes up ~17% of our current practice bank.
59questions here
12free pages
16concepts
Questions 31–35
- 31
While analyzing a Windows executable in x64dbg, a tester sets a breakpoint on a function that processes user input. The tester wants to see the exact bytes being passed to the function and the return address that will be used after the function returns. Which debugger feature should be used?
Select an answer first - 32
A fuzzing campaign produces a crash in a Linux application. The crash report shows a SIGSEGV at a specific address. The tester wants to determine whether the crash is exploitable and what type of memory corruption occurred. Which step is most appropriate?
Select an answer first - 33
A penetration tester receives a binary that is suspected to be a Mach-O executable. The tester wants to confirm the file format and inspect its load commands. Which tool is most appropriate?
Select an answer first - 34
What is the purpose of ASLR (Address Space Layout Randomization)?
Select an answer first - 35
Which fuzzing framework is often used for protocol-based fuzzing and allows defining data models for network protocols?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.