Courseiva
Antivirus Evasion →hardMultiple Choice

PEN-200 Antivirus Evasion Practice Question

A penetration tester has a working unmanaged PowerShell runner in C# that executes a script block on a Windows 10 host with AMSI enabled. The runner currently fails because AMSI scans the script content. The tester wants to disable AMSI scanning for the current process without touching files on disk and without requiring administrative privileges. Which technique best fits these constraints?

⚠ Common exam trap

It's easy for candidates to confuse PowerShell's execution policy, which governs script running, with AMSI, which performs content scanning independent of that policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Patch the AmsiScanBuffer function in memory by overwriting its first bytes with a return value that indicates a clean scan.

AMSI performs in-process scanning through functions resolved from amsi.dll, most notably AmsiScanBuffer. Because the DLL is loaded into the calling process, a user-mode patch of that function in memory changes scan results for that process only, needs no administrative rights, and writes nothing to disk. Deleting system files, inventing registry policies, or adjusting execution policy do not alter the in-memory scanning path AMSI uses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the registry value HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableAMSI to 1.

    Why it's wrong here

    There is no such supported policy value that disables AMSI for arbitrary processes, so writing it has no effect on scanning behavior. Fabricated registry keys are a common distractor because they look like legitimate policy paths. The scenario also requires no on-disk changes, and registry writes persist on the host, violating that constraint even if the key existed.

  • ✗

    Run the PowerShell runner from a session launched with the -NoProfile and -ExecutionPolicy Bypass switches.

    Why it's wrong here

    ExecutionPolicy controls script execution rules enforced by PowerShell itself, not antimalware scanning. AMSI operates independently of execution policy and still inspects script content passed to it. Launching with those switches may allow the script to run under policy, but AMSI will still scan and may block the malicious content, so this does not address the actual failure described.

  • ✓

    Patch the AmsiScanBuffer function in memory by overwriting its first bytes with a return value that indicates a clean scan.

    Why this is correct

    AMSI resolves AmsiScanBuffer from amsi.dll inside each process. Overwriting the function's prologue in the current process's memory so it returns a benign result causes subsequent scans to report no detection, and this works within the user's own process without admin rights or disk changes. It matches the requirement to disable scanning for the current process only and leaves files untouched.

  • ✗

    Delete the amsi.dll file from C:\Windows\System32 and reboot the target host.

    Why it's wrong here

    Deleting a system DLL from System32 requires administrative privileges and would break other components that depend on AMSI, likely destabilizing the system. It also modifies the host on disk, which the scenario explicitly rules out. Even if it succeeded, a reboot would reload protected system files under Windows File Protection, restoring the DLL and leaving the technique ineffective for the engagement.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.