PEN-200 Antivirus Evasion Practice Question
A penetration tester has a working PowerShell-based stager that is being blocked by AMSI on a Windows 11 target. The tester wants to keep using PowerShell for convenience but needs the stager to run without AMSI inspecting the script content. Which technique most directly targets AMSI's inspection of the script?
⚠ Common exam trap
The trap here is assuming that bypassing execution policy or using an older PowerShell version will also bypass AMSI, when AMSI inspects script content independently of those controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Obfuscate the stager and split it across multiple string concatenations and variable substitutions so the script text does not contain recognizable AMSI signatures.
AMSI inspects PowerShell script content by matching patterns against known malicious code. If the script text no longer contains those patterns, the inspection passes. Obfuscation through string splitting, concatenation, and dynamic construction changes the textual form while preserving the executed logic, so the stager runs. Execution policy and code signing are separate controls, and version downgrade is unreliable on patched Windows 11 systems where AMSI enforcement is not tied to the PowerShell version.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the PowerShell execution policy to Bypass using the -ExecutionPolicy Bypass parameter.
Why it's wrong here
Execution policy is a PowerShell-level safeguard that controls whether scripts may run at all, and AMSI operates independently of it. Even with execution policy bypassed, every script block is submitted to AMSI before execution. The stager would still be inspected and blocked. This technique addresses a different control entirely and does not affect AMSI's ability to scan the script content.
- ✗
Sign the PowerShell script with a trusted code-signing certificate before execution.
Why it's wrong here
Code signing affects trust and execution policy decisions but does not exempt a script from AMSI scanning. AMSI inspects the content of scripts regardless of signature, and a signed script containing malicious patterns is still flagged. Obtaining a trusted certificate for this purpose is also infeasible in an engagement. Signing addresses authenticity, not content inspection, so it does not solve the described problem.
- ✓
Obfuscate the stager and split it across multiple string concatenations and variable substitutions so the script text does not contain recognizable AMSI signatures.
Why this is correct
AMSI scans the script content as it is submitted for execution, matching known malicious patterns. If the script is rewritten so that no contiguous string matches an AMSI signature, the scan passes and the script executes. Techniques such as string splitting, character substitution, and dynamic construction change the textual representation while preserving behavior. This directly targets AMSI's pattern-matching inspection of the script.
- ✗
Run the stager through a PowerShell downgrade to version 2 using the -Version 2 parameter.
Why it's wrong here
Downgrading to PowerShell 2.0 was historically effective because AMSI integration was absent in that version, but AMSI is now enforced by the operating system regardless of the PowerShell version invoked in most patched Windows builds. On a Windows 11 target, the downgrade is either blocked or AMSI still applies. This approach is unreliable on modern systems and does not directly address AMSI's inspection mechanism.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.