PEN-200 Antivirus Evasion Practice Question
A penetration tester modifies a known exploit's payload by changing variable names and adding junk instructions. Despite these changes, the antivirus software still flags the file as 'Trojan.Generic' immediately upon being written to disk. What is the most likely reason for this detection?
⚠ Common exam trap
Candidates often believe that simple obfuscation like renaming variables is sufficient to bypass modern antivirus, failing to realize that heuristic engines analyze the logic and structure of the code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Heuristic analysis identified suspicious code patterns or structures.
While simple obfuscation like renaming variables can bypass basic string-matching signatures, modern antivirus engines use heuristic analysis to identify suspicious patterns or structures common to malware. If the core logic or the arrangement of functional code blocks remains recognizable, the heuristic engine will flag the file based on its similarity to known malicious software families even without an exact match.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The antivirus is using signature-based detection on the specific junk code.
Why it's wrong here
Junk code is typically unique or randomized, making it an unlikely candidate for a static signature in a database. Antivirus vendors focus their signatures on the functional parts of the malware that are difficult to change, rather than the decorative or filler instructions that an attacker adds specifically to disrupt simple pattern matching.
- ✓
Heuristic analysis identified suspicious code patterns or structures.
Why this is correct
Heuristic engines look for characteristics and behaviors rather than exact byte sequences. By identifying that the file structure or the sequence of API calls closely resembles known malware, the antivirus can make an educated guess that the file is malicious, even if the specific strings and variables have been altered by the penetration tester.
- ✗
The file's entropy was too low, triggering an automatic quarantine.
Why it's wrong here
Low entropy indicates a file is likely plain text or highly structured, which is common for legitimate applications. High entropy usually triggers suspicion as it suggests encryption or packing, which are common traits of malware. Therefore, low entropy would not typically be the reason for a 'Trojan.Generic' detection in this specific scenario.
- ✗
The junk instructions were identified as malicious shellcode by the CPU.
Why it's wrong here
CPUs do not have built-in antivirus capabilities to identify malicious intent in instructions; they simply execute whatever valid code is provided. Security features like Data Execution Prevention (DEP) can prevent execution in certain memory regions, but they do not analyze the logic of 'junk' instructions to determine if they belong to a Trojan.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.