PEN-200 Antivirus Evasion Practice Question
An operator is analyzing why a compiled C# stager payload was flagged immediately by Windows Defender despite having a completely unique cryptographic hash. Which AV detection mechanism is most likely responsible for flagging the binary based on internal structure rather than known file signatures?
⚠ Common exam trap
Many beginners believe that changing a file hash via padding guarantees evasion, ignoring that structural heuristics and API imports are heavily analyzed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Heuristic analysis evaluating suspicious API imports, section characteristics, and code patterns indicative of stagers.
Heuristic and behavioral engines examine internal characteristics, structural layouts, and API import patterns rather than relying strictly on known file hashes. If a binary imports suspicious combinations of memory allocation and execution APIs, heuristics flag it as malicious even if the file has never been seen before.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud-based cryptographic hash lookup databases containing global blacklists of known malware samples.
Why it's wrong here
Cryptographic hash databases match files against known lists of bad hashes. Since the stager was freshly compiled with a unique hash, it would not match any existing entry in a static hash blacklist unless the exact binary was previously submitted.
- ✗
Static signature matching using rigid byte sequences extracted from older malware variants.
Why it's wrong here
Static signature matching looks for exact byte strings associated with known threats. A freshly compiled custom C# stager will not contain these exact historical byte sequences, ruling out simple signature matches as the primary trigger.
- ✓
Heuristic analysis evaluating suspicious API imports, section characteristics, and code patterns indicative of stagers.
Why this is correct
Heuristic analysis analyzes the structural makeup of an executable, including imported DLLs like VirtualAlloc and CreateThread. When these suspicious API combinations appear together in an unknown binary, the engine flags it as a potential threat based on risk scoring.
- ✗
Network signature inspection monitoring incoming HTTP traffic headers for default command and control strings.
Why it's wrong here
Network inspection analyzes packets passing through interfaces rather than inspecting local files on disk. If the binary was flagged immediately upon writing to disk or compilation, network traffic analysis has not yet played a role in the detection.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.