PEN-200 Antivirus Evasion Practice Question
A tester is preparing a reverse shell executable for a Windows target protected by a signature-based antivirus product. To reduce the chance the file is flagged, the tester wants to modify the binary so it no longer matches known signatures while keeping its behavior. Which action best accomplishes this?
⚠ Common exam trap
The trap here is believing that cosmetic metadata like icons or version strings, or the file's location, affects content-based signature matching when scanners examine the executable's bytes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Recompile the source after renaming functions and adding benign junk instructions, then rebuild the binary.
Signature-based detection compares file bytes against known patterns derived from code, strings, and embedded payloads. Altering the source so the compiled binary's byte sequence changes, such as renaming functions and inserting junk instructions, breaks that match while preserving functionality. Metadata edits, directory changes, and privilege elevation leave the underlying bytes intact, so the original signature continues to identify the file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run the executable with administrator privileges so it can bypass user-level scanning hooks.
Why it's wrong here
Antivirus real-time scanning is not limited to user-level hooks; kernel components and minifilters also scan file access. Elevated execution does not exempt a process from content-based detection, and running as administrator often increases monitoring. The executable's bytes are unchanged, so any signature matching them still triggers regardless of the privilege level used to launch the process.
- ✗
Move the executable from the Downloads folder to a less commonly scanned directory such as C:\Temp.
Why it's wrong here
Signature-based detection matches file content regardless of the directory it resides in. Real-time scanners monitor writes and executions across the filesystem, so relocating the file does not prevent scanning. The same bytes remain, so the same signature continues to match. Directory choice might affect other controls or logging, but it is irrelevant to defeating content-based signature matching.
- ✗
Change the file's icon and version information resource to mimic a legitimate application.
Why it's wrong here
Icons and version resources live in the PE resource section and are not part of the code signature that scanners match against executable behavior. Modifying them changes only metadata, leaving the compiled instructions and any embedded payload bytes unchanged. A signature that matches the code or payload still fires, so this cosmetic change does not meaningfully reduce static detection for the scenario described.
- ✓
Recompile the source after renaming functions and adding benign junk instructions, then rebuild the binary.
Why this is correct
Static signatures often include byte sequences from compiled code, strings, and payload data. Renaming functions and inserting junk instructions alters the compiled output's byte layout and instruction sequence while preserving the program's logic. Rebuilding produces a new binary whose bytes no longer match the original signature, which directly addresses signature matching without changing behavior, matching the tester's stated goal.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.