PEN-200 Antivirus Evasion Practice Question
A tester is targeting a Windows machine and notices that a specific legitimate application regularly looks for a COM object that is missing from the HKEY_CURRENT_USER (HKCU) registry hive, eventually falling back to HKEY_LOCAL_MACHINE (HKLM). How can this be exploited for evasion?
⚠ Common exam trap
Candidates often confuse this with DLL Hijacking. While the mechanism uses a malicious DLL, the core exploit here is the manipulation of the registry to redirect COM object loading.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
By hijacking the COM object to execute code under a trusted process.
This scenario describes COM Hijacking. By creating the missing registry key in HKCU, the attacker can redirect the application to load a malicious DLL. Since HKCU is searchable before HKLM and can be modified without administrative privileges, this allows for persistent execution of code within a trusted process while bypassing alerts that might trigger on more obvious persistence methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
By performing a privilege escalation to modify the HKLM hive.
Why it's wrong here
The beauty of COM Hijacking in HKCU is that it does not require administrative privileges or HKLM modification. The user has permission to write to their own HKCU hive by default. Modifying HKLM would be more difficult and more likely to be flagged by security software as a suspicious system-wide change.
- ✓
By hijacking the COM object to execute code under a trusted process.
Why this is correct
Because the application searches HKCU first, it will find and use the attacker's malicious COM mapping instead of the legitimate one in HKLM. This results in the trusted application loading the attacker's DLL. This is an effective evasion technique because the malicious activity is masked by the legitimate process's identity.
- ✗
By using the missing key to trigger a buffer overflow in the application.
Why it's wrong here
COM Hijacking is a logic-based redirection attack rather than a memory corruption exploit. While a missing key might cause an error, it does not inherently provide a path to a buffer overflow. The goal here is to use the existing, legitimate functionality of the COM subsystem to load a malicious library.
- ✗
By deleting the HKLM key to force the application to use HKCU.
Why it's wrong here
The application already searches HKCU first by design; there is no need to delete the HKLM key. Furthermore, deleting keys in HKLM requires administrative privileges, which defeats the purpose of an evasion technique that is often used precisely because it can be implemented with standard user-level permissions in the HKCU hive.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.