Courseiva
Antivirus Evasion →mediumMultiple Choice

PEN-200 Antivirus Evasion Practice Question

A tester is targeting a Windows machine and notices that a specific legitimate application regularly looks for a COM object that is missing from the HKEY_CURRENT_USER (HKCU) registry hive, eventually falling back to HKEY_LOCAL_MACHINE (HKLM). How can this be exploited for evasion?

⚠ Common exam trap

Candidates often confuse this with DLL Hijacking. While the mechanism uses a malicious DLL, the core exploit here is the manipulation of the registry to redirect COM object loading.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

By hijacking the COM object to execute code under a trusted process.

This scenario describes COM Hijacking. By creating the missing registry key in HKCU, the attacker can redirect the application to load a malicious DLL. Since HKCU is searchable before HKLM and can be modified without administrative privileges, this allows for persistent execution of code within a trusted process while bypassing alerts that might trigger on more obvious persistence methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    By performing a privilege escalation to modify the HKLM hive.

    Why it's wrong here

    The beauty of COM Hijacking in HKCU is that it does not require administrative privileges or HKLM modification. The user has permission to write to their own HKCU hive by default. Modifying HKLM would be more difficult and more likely to be flagged by security software as a suspicious system-wide change.

  • ✓

    By hijacking the COM object to execute code under a trusted process.

    Why this is correct

    Because the application searches HKCU first, it will find and use the attacker's malicious COM mapping instead of the legitimate one in HKLM. This results in the trusted application loading the attacker's DLL. This is an effective evasion technique because the malicious activity is masked by the legitimate process's identity.

  • ✗

    By using the missing key to trigger a buffer overflow in the application.

    Why it's wrong here

    COM Hijacking is a logic-based redirection attack rather than a memory corruption exploit. While a missing key might cause an error, it does not inherently provide a path to a buffer overflow. The goal here is to use the existing, legitimate functionality of the COM subsystem to load a malicious library.

  • ✗

    By deleting the HKLM key to force the application to use HKCU.

    Why it's wrong here

    The application already searches HKCU first by design; there is no need to delete the HKLM key. Furthermore, deleting keys in HKLM requires administrative privileges, which defeats the purpose of an evasion technique that is often used precisely because it can be implemented with standard user-level permissions in the HKCU hive.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.