Courseiva
Antivirus Evasion →mediumMultiple Choice

PEN-200 Antivirus Evasion Practice Question

A penetration tester has obtained a low-privilege shell on a Windows 10 host protected by Windows Defender with real-time protection enabled. The tester wants to execute a custom .NET assembly in memory to avoid writing a payload to disk, but Defender's AMSI integration repeatedly flags the assembly when loaded via the standard reflection technique. Which modification to the in-memory loading approach is MOST likely to prevent AMSI from inspecting the assembly's content?

⚠ Common exam trap

The trap here is assuming that encrypting or encoding the payload hides it from AMSI, when AMSI inspects the decrypted buffer at the moment the runtime submits it for scanning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Patch the AmsiScanBuffer function in amsi.dll in the current process before loading the assembly.

AMSI integrates with the .NET runtime and submits assembly content to AmsiScanBuffer before execution. Patching that function in the current process causes the scan to return a benign result, allowing the in-memory assembly to load without Defender receiving the buffer. Encryption, encoding, and remote loading do not prevent the runtime from passing the decrypted or fetched bytes to AMSI, so they fail against runtime inspection even though they may help against static file signatures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Base64-encode the assembly bytes and load them with Assembly.LoadFrom after decoding.

    Why it's wrong here

    Base64 encoding only changes the textual representation of the bytes; once decoded, the original assembly is reconstructed and passed to the runtime. AMSI inspects the decoded content at the point of assembly load, so encoding provides no protection against runtime scanning. This approach is useful for evading static string-based signatures in scripts, but it does not defeat AMSI's inspection of the loaded assembly.

  • ✓

    Patch the AmsiScanBuffer function in amsi.dll in the current process before loading the assembly.

    Why this is correct

    AMSI ultimately routes assembly and script content through AmsiScanBuffer in amsi.dll. By overwriting the function prologue in the current process with a stub that returns a clean result, the tester prevents Defender from receiving the buffer for inspection. This is a classic runtime AMSI bypass that works for .NET assembly loads because the CLR calls into AMSI via that same exported function. It does not require disabling Defender globally.

  • ✗

    Store the assembly on a remote SMB share and load it with Assembly.LoadFrom over the network path.

    Why it's wrong here

    Loading over SMB changes where the file resides, not how it is inspected. Assembly.LoadFrom still reads the assembly bytes into the process and the CLR submits them to AMSI before execution, so Defender can still flag the content. Remote loading may bypass some file-based controls, but it does not address AMSI's runtime buffer scan, leaving the assembly detectable when loaded.

  • ✗

    Encrypt the assembly with AES and decrypt it directly into a memory region allocated with PAGE_EXECUTE_READWRITE.

    Why it's wrong here

    Allocating PAGE_EXECUTE_READWRITE and decrypting into it does not hide the assembly from AMSI, because AMSI scans the buffer when it is passed to the scripting or .NET runtime interfaces, not merely when memory is written. The encrypted bytes are decrypted before execution, and the decrypted content is still submitted to AMSI through the normal assembly-loading APIs. This technique mainly evades static file scanning, not runtime AMSI inspection.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.