Courseiva
Antivirus Evasion →mediumMultiple Choice

PEN-200 Antivirus Evasion Practice Question

An ethical hacker wants to evade signature-based detection while developing a custom reverse shell loader for a PEN-200 lab assignment. Which technique fundamentally alters the binary's byte signatures without modifying its core execution logic or breaking the payload?

⚠ Common exam trap

Candidates often confuse static encryption with process injection, assuming that hiding the payload on disk automatically bypasses behavioral monitoring during runtime execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Applying XOR encoding to the payload buffer and implementing a custom runtime stub to decrypt it in memory.

Encoding or encrypting the payload alters static byte signatures that antivirus engines use to flag known malicious files. By decoding the payload dynamically in memory at runtime, the payload remains obfuscated on disk, preventing signature detection while preserving the exact execution logic required for the reverse shell to successfully connect back to the attacking machine.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Stripping all debugging symbols and symbol tables from the executable using strip.

    Why it's wrong here

    Stripping debugging symbols removes developer metadata and function names, but it leaves the core executable code and byte patterns entirely intact. Antivirus engines primarily scan the actual executable code sections, making symbol stripping insufficient for evading robust signatures.

  • ✗

    Modifying the file extension from .exe to .scr to trick the operating system shell.

    Why it's wrong here

    Changing a file extension is a simple social engineering trick that does not alter the underlying binary data or byte signatures. Modern antivirus solutions analyze file magic bytes and headers rather than relying on the extension, rendering this method ineffective against automated detection.

  • ✓

    Applying XOR encoding to the payload buffer and implementing a custom runtime stub to decrypt it in memory.

    Why this is correct

    XOR encoding modifies every byte of the payload based on a key, entirely changing the static file hashes and byte signatures. A custom runtime stub allocates memory, decrypts the payload on the fly, and executes it without ever writing the cleartext binary back to disk.

  • ✗

    Compressing the final executable binary using standard ZIP archiving utilities without a password.

    Why it's wrong here

    Standard compression algorithms reorganize data streams, but most modern antivirus scanners automatically inspect inside standard archives. Unless the archive is encrypted with a strong password that prevents unpacking, the scanner will easily extract and inspect the malicious payload inside.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.