Courseiva
Antivirus Evasion →easyMultiple Choice

PEN-200 Antivirus Evasion Practice Question

A junior penetration tester is preparing a payload for a Windows 10 target and wants to avoid signature-based detection by changing the binary's appearance without altering its functionality. Which technique is specifically designed to achieve this?

⚠ Common exam trap

The trap here is assuming that packing or splitting a payload changes its signature, when those methods either get unpacked by AV or leave the original bytes intact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Encoding the payload with msfvenom's shikata_ga_nai encoder multiple times.

Shikata_ga_nai is a polymorphic encoder that mutates the payload's bytes while preserving its functionality, directly targeting signature-based detection by changing the binary appearance. The other options either do not alter the binary signature, are easily unpacked, or change only the delivery mechanism rather than the payload's bytes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Splitting the payload into multiple chunks and reassembling at runtime.

    Why it's wrong here

    Splitting the payload into chunks and reassembling at runtime can evade some static scans, but it requires a custom loader and does not inherently change the binary appearance of the payload itself. The signature of the reassembled payload may still match known detections. This approach is more about obfuscation through fragmentation than about altering the binary signature of the payload.

  • ✗

    Running the payload from a remote SMB share instead of the local disk.

    Why it's wrong here

    Executing from a remote SMB share changes the delivery mechanism but not the binary appearance of the payload. The file's bytes remain identical, so signature-based detection will still match if the payload is scanned. This technique may bypass some local disk-based controls, but it does not address the goal of altering the binary's appearance to evade signature detection.

  • ✓

    Encoding the payload with msfvenom's shikata_ga_nai encoder multiple times.

    Why this is correct

    Shikata_ga_nai is an encoder that transforms the payload's bytes using a polymorphic XOR additive feedback loop, changing the binary appearance while preserving functionality. Applying it multiple times further mutates the signature, which can help evade static signature-based detection. This is a classic PEN-200 technique for altering the file's binary appearance without changing what the payload does.

  • ✗

    Compressing the payload with UPX to reduce its size.

    Why it's wrong here

    UPX is a packer that compresses the executable, which can change the file's hash and reduce size, but many AV engines unpack UPX-packed files and inspect the original code. UPX is also widely used by legitimate and malicious software alike, so its presence alone is a weak evasion signal. It does not provide the polymorphic mutation that specifically targets signature-based detection.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.