Courseiva
Antivirus Evasion →mediumMultiple Choice

PEN-200 Antivirus Evasion Practice Question

A penetration tester delivers a custom .NET executable to a Windows 10 host running Microsoft Defender with cloud-delivered protection enabled. The binary contains an embedded shellcode blob in its .data section. After the loader decrypts the shellcode in memory and begins executing it, Defender terminates the process even though the file itself never touched disk again. Which technique would most directly address this specific detection?

⚠ Common exam trap

The trap here is assuming that any obfuscation of the shellcode bytes will defeat Defender, when the detection is triggered by the memory protection state at execution time rather than the file contents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change the shellcode's allocation from VirtualAlloc with PAGE_EXECUTE_READWRITE to VirtualAlloc with PAGE_READWRITE, then use VirtualProtect to flip the page to PAGE_EXECUTE_READ just before invoking the shellcode.

The detection is behavioral and memory-resident, so the fix must change how memory is allocated and protected. Marking a single region both writable and executable is a classic high-signal indicator that Defender's behavioral engine correlates with shellcode loaders. Allocating writable, writing the payload, and then re-protecting the page as executable removes that indicator while still allowing the shellcode to run. Encoding, compiler flags, and static obfuscation do not affect the in-memory execution profile.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Base64-encode the shellcode and decode it immediately before calling CreateThread.

    Why it's wrong here

    Base64 is a reversible encoding, not encryption, and Defender's emulation and behavioral layers can trivially decode it during dynamic analysis. More importantly, the encoding only affects how bytes are stored prior to execution; once decoded into memory, the shellcode executes identically and the same behavioral indicators fire. This addresses static storage, not the runtime memory behavior that caused termination.

  • ✓

    Change the shellcode's allocation from VirtualAlloc with PAGE_EXECUTE_READWRITE to VirtualAlloc with PAGE_READWRITE, then use VirtualProtect to flip the page to PAGE_EXECUTE_READ just before invoking the shellcode.

    Why this is correct

    Defender's behavioral engine commonly flags a single allocation that is simultaneously writable and executable, since legitimate code rarely needs RWX pages. Allocating as RW, writing the decrypted shellcode, then flipping to RX via VirtualProtect mimics how a normal loader maps code and removes the RWX indicator. The shellcode still executes, but the high-signal memory characteristic that triggered termination is eliminated.

  • ✗

    Encrypt the shellcode with XOR and decrypt it at runtime using a stack-based routine.

    Why it's wrong here

    Encrypting the shellcode only defeats static file scanning; once the loader decrypts it into a readable buffer in memory, Defender's behavioral engine can still inspect the region and terminate the process. The scenario states the file never touched disk again, so the detection is memory-based, not signature-based on disk. Encrypting the blob does not change the in-memory behavior that triggered termination.

  • ✗

    Recompile the loader with the /GS- flag to disable stack cookies and reduce the binary's static footprint.

    Why it's wrong here

    Disabling stack cookies alters compiler hardening metadata but has no bearing on how Defender evaluates in-memory shellcode execution. Stack cookies are a mitigation against buffer overflows, not an evasion primitive. The scenario's detection occurs after the shellcode is decrypted and executing in memory, so compiler flags that only affect the on-disk PE structure will not change the runtime behavior being flagged.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.