20+ practice questions focused on Antivirus Evasion — one of the most tested topics on the OffSec PEN-200 / OSCP Concepts exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Antivirus Evasion PracticeAn advanced evasion tool uses direct system calls (Syscalls) by extracting the syscall numbers from ntdll.dll and executing them using assembly. What is the primary advantage of this approach over using standard Windows API functions like NTWriteVirtualMemory?
Explanation: Endpoint Detection and Response (EDR) solutions typically monitor user-mode activity by 'hooking' common Windows API functions in ntdll.dll. When an application calls a hooked function, the EDR intercepts the call to inspect it. By using direct syscalls, an attacker bypasses these hooks entirely, communicating directly with the kernel and avoiding detection by the EDR's user-mode monitoring agents.
An ethical hacker is developing a custom C# loader to bypass Windows Defender on an engagement. The analyst notices that a simple reverse shell payload containing clear strings like 'cmd.exe' is immediately flagged on disk. Which technique is most effective for obfuscating these critical strings within the binary to prevent static signature detection?
Explanation: Encrypting or encoding critical strings like command execution binaries prevents signature scanners from matching known malicious patterns statically on disk. In OSCP-style engagements, relying on basic plaintext strings leaves binaries vulnerable to signature matching. Transforming these strings dynamically at runtime ensures the static footprint remains clean while preserving the functional behavior required during post-exploitation activities.
During an assessment, a penetration tester attempts to execute a staged Meterpreter payload via PowerShell, but AMSI (Antisimalware Scan Interface) blocks the script execution. Which TWO techniques can the tester employ to bypass or disable AMSI inspection effectively within the PowerShell session?
Explanation: Bypassing AMSI is a fundamental skill for penetration testers operating within hardened Windows environments. Patching the amsiInitFailed function or overwriting the amsiContext buffer in memory effectively blinds the scanning interface, allowing subsequent malicious script blocks to execute without triggering inline antivirus alerts during red team operations.
You are attempting to deliver a custom payload to a target machine protected by signature-based antivirus. Despite obfuscating the payload, the AV continues to flag the binary on disk. Which technique is most effective at preventing the AV from performing static analysis on the file structure?
Explanation: Static analysis often relies on detecting known patterns in the file headers and sections. By using custom packers or encrypting the payload in transit, you prevent the antivirus engine from identifying suspicious strings or imported functions. This is a fundamental evasion technique in the OSCP workflow because static signatures are the first line of defense; if the binary structure appears benign or randomized, the engine must trigger dynamic analysis, which is significantly more resource-intensive.
You are preparing a payload for a Windows environment with AMSI enabled. Which TWO of the following strategies are most effective at evading AMSI-based detection during the execution of script-based payloads?
Explanation: AMSI scans script content in memory before execution, making it a major hurdle for living-off-the-land techniques. Bypassing AMSI involves either neutralizing the inspection engine within the process memory or obfuscating the script to the point where the signature engine fails to identify it as malicious. These methods are vital for maintaining persistence or executing post-exploitation scripts without triggering immediate alerts from the Windows Defender engine during your engagement.
+15 more Antivirus Evasion questions available
Practice all Antivirus Evasion questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Antivirus Evasion. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Antivirus Evasion questions on the PEN-200 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Antivirus Evasion is tested as part of the OffSec PEN-200 / OSCP Concepts blueprint. Practicing with targeted Antivirus Evasion questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free PEN-200 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Antivirus Evasion is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Antivirus Evasion practice session with instant scoring and detailed explanations.
Start Antivirus Evasion Practice →