PEN-200 Antivirus Evasion Practice Question
A penetration tester needs to deliver a Meterpreter payload to a Windows target protected by an EDR that performs both static file scanning and behavioral monitoring of process creation. The tester wants to reduce the chance of detection during initial execution while still obtaining a session. Which two techniques most directly reduce detection in this combined scenario? (Choose two.)
⚠ Common exam trap
The trap here is treating static obfuscation and behavioral evasion as interchangeable, when the scenario explicitly includes both controls and requires a technique that addresses each one separately.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spawn the payload by injecting into a legitimate, already-running process such as explorer.exe rather than starting a new process.
The scenario involves two distinct controls: static file scanning and behavioral process monitoring. A custom loader with encrypted shellcode removes recognizable bytes from disk, defeating static signatures. Injecting into an existing trusted process avoids the new-process creation event that behavioral engines monitor, placing execution inside a process already deemed legitimate. Together these address both controls. Renaming, UPX packing, and registry tampering either leave the static bytes intact or generate their own high-signal events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable Windows Defender real-time protection by modifying the registry before executing the payload.
Why it's wrong here
Modifying Defender registry keys requires elevated privileges and generates high-severity alerts in most EDR deployments, often triggering immediate response before the payload ever runs. The scenario specifies an EDR that is separate from Defender and performs behavioral monitoring, so tampering with Defender settings does not address the EDR at all. This approach increases visibility rather than reducing it.
- ✗
Rename the payload executable to svchost.exe and place it in the user's temp directory.
Why it's wrong here
Renaming a file does not change its contents, so static scanning still matches the payload bytes on disk. The behavioral layer also observes the actual behavior of the process regardless of its filename; invoking a binary named svchost.exe from a temp directory is itself a suspicious indicator that EDR products flag. This technique neither defeats static scanning nor reduces behavioral detection, making it ineffective here.
- ✓
Spawn the payload by injecting into a legitimate, already-running process such as explorer.exe rather than starting a new process.
Why this is correct
EDR behavioral monitoring often flags the creation of a new, unsigned process that immediately performs suspicious actions. Injecting into an existing trusted process like explorer.exe avoids a new process creation event and places the malicious code inside a process the EDR considers benign. This directly addresses the behavioral monitoring component described in the scenario.
- ✗
Compress the payload with UPX and deliver it as a self-extracting archive.
Why it's wrong here
UPX is a well-known packer, and EDR and antivirus engines routinely unpack UPX-compressed binaries before scanning, so the original payload bytes are still analyzed. Self-extracting archives add another executable stage that behavioral monitoring can flag. Compression does not remove the static signature and does not change the runtime behavior that the EDR observes, so it does not address either control described in the scenario.
- ✓
Use a custom loader that stores the shellcode encrypted and decrypts it into memory only at runtime.
Why this is correct
Encrypting the shellcode and decrypting it at runtime means the on-disk file contains no recognizable payload bytes, defeating static signature scanning. The behavioral layer may still observe the decryption and execution, but the static detection vector is removed, which is one of the two controls described. Combined with a technique that addresses behavior, this significantly reduces the overall detection surface.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.