Courseiva
Antivirus Evasion →hardMultiple Choice

PEN-200 Antivirus Evasion Practice Question

A penetration tester uses process hollowing to hide their payload inside 'svchost.exe'. They start the process in a suspended state, unmap its memory, write their shellcode, and resume the thread. What is a specific indicator that an advanced EDR might use to detect this activity?

⚠ Common exam trap

Candidates often suggest 'the process is running as SYSTEM'. While true, EDRs look for specific memory-based indicators, not just process privileges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The entry point of the process in memory differs from the image on disk.

Process hollowing is a powerful evasion technique, but it leaves behind traces in the system's memory and process metadata. Advanced EDR solutions monitor for discrepancies between the file on disk and the code in memory. They also track specific API call sequences, such as creating a process in a suspended state followed immediately by memory unmapping and cross-process writing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The 'svchost.exe' process will show a significantly higher CPU usage.

    Why it's wrong here

    Process hollowing itself does not inherently cause high CPU usage. The resource consumption depends entirely on what the injected shellcode does. If the malicious code is a quiet beacon or a keylogger, it will use very little CPU, making this an unreliable indicator for detecting the hollowing technique itself during a scan.

  • ✓

    The entry point of the process in memory differs from the image on disk.

    Why this is correct

    EDR tools can compare the executable's entry point and memory map against the original file on disk. When a process is hollowed, the memory contents and the entry point are modified to point to the malicious code. This mismatch is a clear sign that the process has been tampered with and is no longer legitimate.

  • ✗

    The process will be unable to communicate with the network.

    Why it's wrong here

    Hollowing a process does not restrict its network capabilities. In fact, attackers often hollow processes like 'svchost.exe' or 'explorer.exe' precisely because they are expected to have network activity. The injected code can use the process's existing privileges and handles to establish outbound connections to a command and control server.

  • ✗

    The system will automatically restart the process due to a checksum error.

    Why it's wrong here

    Windows does not perform continuous checksum verification of running process memory against the original executable on disk. While some integrity checks exist for signed system files, they do not trigger a restart of a hollowed process. The process will continue to run the malicious code until it is manually terminated or the system crashes.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.