PEN-200 Antivirus Evasion Practice Question
An attacker places a malicious 'version.dll' file into the same directory as a legitimate, signed executable that is known to load that DLL. When the legitimate program starts, it loads the malicious DLL instead of the one in the System32 folder. What evasion technique is being demonstrated?
⚠ Common exam trap
Candidates often confuse DLL Sideloading with DLL Hijacking or Search Order Hijacking. While related, Sideloading specifically refers to placing a malicious DLL alongside a legitimate executable to exploit the default search order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DLL Sideloading
DLL Sideloading exploits the default search order that Windows uses to locate dynamic-link libraries. By placing a malicious DLL in the application's local directory, the attacker ensures it is loaded before the legitimate system DLL. This allows malicious code to run under the context of a trusted, signed process, which often bypasses security controls and behavioral alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DLL Injection
Why it's wrong here
DLL Injection involves forcing a running process to load a DLL from an external source, typically using APIs like CreateRemoteThread and LoadLibrary. In the scenario described, the process loads the DLL naturally during its startup routine due to the file's location, rather than being forced to do so by an external actor after execution.
- ✓
DLL Sideloading
Why this is correct
Sideloading takes advantage of the Windows DLL search order, which prioritizes the application's directory over system directories. By naming the malicious file after a required dependency, the attacker tricks a trusted application into executing their code. This is a highly effective way to gain execution while appearing as a legitimate, signed process.
- ✗
COM Hijacking
Why it's wrong here
COM Hijacking involves modifying registry keys to redirect Component Object Model (COM) object lookups to a malicious DLL. While it also involves loading a DLL, it relies on registry manipulation rather than the file system search order. The scenario specifically mentions placing a file in the same directory as an executable, indicating sideloading.
- ✗
Reflective DLL Loading
Why it's wrong here
Reflective DLL loading is a technique where a DLL is loaded into a process's memory without using the standard Windows loader or touching the disk. In the described scenario, the DLL is explicitly placed on the disk in a specific directory, which contradicts the 'stealth' and 'memory-only' nature of reflective loading techniques.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.