Courseiva

CCNA Antivirus Evasion Questions

34 questions · Antivirus Evasion · All types, answers revealed

1
MCQhard

You are tasked with delivering a Meterpreter payload to a Windows Server 2019 target protected by a next-generation antivirus that performs userland API hooking on NtAllocateVirtualMemory and NtProtectVirtualMemory. Your current C loader uses these APIs directly and is detected. Which technique is most appropriate to bypass the userland hooks without requiring kernel-level privileges?

A.Install a kernel-mode driver to remove the hooks from ntdll and restore original bytes.
B.Encrypt the payload with AES and decrypt it in memory just before execution.
C.Direct system calls by manually constructing the syscall stub and invoking the syscall instruction.
D.Use PowerShell's Add-Type to compile the loader in memory, relying on the .NET runtime to bypass native hooks.
AnswerC

Manually building the syscall stub bypasses userland hooks because the hook resides in ntdll's exported function, not in the kernel transition path. By placing the syscall number in EAX and executing the syscall instruction directly, the loader skips the modified ntdll code entirely. This works without kernel privileges and is a standard PEN-200 technique for evading EDR hooks on memory allocation and protection APIs.

Why this answer

Direct system calls bypass userland API hooks because the hooks are placed in ntdll's exported functions, and invoking the syscall instruction directly skips that code. The other options either require kernel privileges, still transit the hooked APIs, or only address static detection rather than the behavioral hooks causing the detection.

Exam trap

The trap here is believing that in-memory compilation or payload encryption changes the API call path, when both still invoke the hooked ntdll functions.

2
MCQeasy

A penetration tester modifies a known exploit's payload by changing variable names and adding junk instructions. Despite these changes, the antivirus software still flags the file as 'Trojan.Generic' immediately upon being written to disk. What is the most likely reason for this detection?

A.The antivirus is using signature-based detection on the specific junk code.
B.Heuristic analysis identified suspicious code patterns or structures.
C.The file's entropy was too low, triggering an automatic quarantine.
D.The junk instructions were identified as malicious shellcode by the CPU.
AnswerB

Heuristic engines look for characteristics and behaviors rather than exact byte sequences. By identifying that the file structure or the sequence of API calls closely resembles known malware, the antivirus can make an educated guess that the file is malicious, even if the specific strings and variables have been altered by the penetration tester.

Why this answer

While simple obfuscation like renaming variables can bypass basic string-matching signatures, modern antivirus engines use heuristic analysis to identify suspicious patterns or structures common to malware. If the core logic or the arrangement of functional code blocks remains recognizable, the heuristic engine will flag the file based on its similarity to known malicious software families even without an exact match.

Exam trap

Candidates often believe that simple obfuscation like renaming variables is sufficient to bypass modern antivirus, failing to realize that heuristic engines analyze the logic and structure of the code.

3
MCQeasy

Why is using the default 'msfvenom' encoders like 'shikata_ga_nai' often insufficient for bypassing modern antivirus solutions?

A.They only work on 32-bit systems and are ignored by 64-bit AV.
B.The encoders increase the file size, making it look suspicious.
C.The decoding stubs have well-known, static signatures.
D.They use encryption that is easily decrypted by the AV engine.
AnswerC

Antivirus vendors include the signatures for common Metasploit encoder stubs in their databases. Even though the payload itself is 'randomized' by the encoder, the small piece of code that decrypts that payload remains recognizable. Since this stub must run first, the antivirus identifies it immediately and blocks the execution before the payload is even unpacked.

Why this answer

Metasploit encoders were originally designed to remove 'bad characters' from shellcode to ensure it would run correctly in an exploit. They were not primarily intended for antivirus evasion. Because these encoders are open-source and widely used, antivirus vendors have had years to develop highly accurate signatures for the decoding stubs they generate, making them easily detectable.

Exam trap

Candidates mistakenly believe msfvenom encoders are security features. They are functional tools for payload delivery, and their signatures are widely known by AV engines.

4
MCQmedium

When analyzing the memory of a compromised system, you find that your shellcode is being detected by behavioral monitoring. What is the most effective approach to reduce the likelihood of detection by EDR systems during process injection?

A.Increasing the sleep interval between shellcode execution stages.
B.Utilizing indirect syscalls to execute memory operations without triggering API hooks.
C.Injecting the shellcode into a low-privilege process to minimize impact.
D.Replacing the shellcode with an equivalent set of PowerShell commands.
AnswerB

Indirect syscalls bypass the user-mode hooks installed by EDRs in common Windows APIs like NtAllocateVirtualMemory. By invoking the kernel directly from the assembly, the shellcode avoids passing through monitored functions, effectively blinding the EDR to the memory allocation process, which is the primary indicator of malicious injection.

Why this answer

Behavioral detection focuses on suspicious API calls, such as VirtualAllocEx and WriteProcessMemory, being called by an unauthorized or unexpected process. By using indirect syscalls or alternative memory allocation methods, you can bypass the hooks that security products place on high-level Windows APIs. This is critical in modern testing because EDRs monitor process interactions in real-time, making standard injection techniques trivial for security software to identify and block immediately.

Exam trap

Candidates frequently confuse direct API calls with evasion techniques, assuming standard process injection methods are stealthy enough to bypass modern EDR behavioral monitoring without modifications.

5
MCQmedium

A tester is targeting a Windows machine and notices that a specific legitimate application regularly looks for a COM object that is missing from the HKEY_CURRENT_USER (HKCU) registry hive, eventually falling back to HKEY_LOCAL_MACHINE (HKLM). How can this be exploited for evasion?

A.By performing a privilege escalation to modify the HKLM hive.
B.By hijacking the COM object to execute code under a trusted process.
C.By using the missing key to trigger a buffer overflow in the application.
D.By deleting the HKLM key to force the application to use HKCU.
AnswerB

Because the application searches HKCU first, it will find and use the attacker's malicious COM mapping instead of the legitimate one in HKLM. This results in the trusted application loading the attacker's DLL. This is an effective evasion technique because the malicious activity is masked by the legitimate process's identity.

Why this answer

This scenario describes COM Hijacking. By creating the missing registry key in HKCU, the attacker can redirect the application to load a malicious DLL. Since HKCU is searchable before HKLM and can be modified without administrative privileges, this allows for persistent execution of code within a trusted process while bypassing alerts that might trigger on more obvious persistence methods.

Exam trap

Candidates often confuse this with DLL Hijacking. While the mechanism uses a malicious DLL, the core exploit here is the manipulation of the registry to redirect COM object loading.

6
Multi-Selectmedium

Which THREE 'Living off the Land' (LotL) binaries are frequently used by penetration testers to download or execute malicious code while bypassing basic antivirus restrictions?

Select 3 answers
A.certutil.exe
B.mshta.exe
C.regsvr32.exe
D.calc.exe
E.notepad.exe
AnswersA, B, C

Certutil is a command-line program for managing certificates, but it includes a '-urlcache -split -f' parameter that allows it to download files from the internet. Because it is a trusted system utility, many basic antivirus programs and firewall rules do not flag it when it initiates a network connection to retrieve a file.

Why this answer

Living off the Land binaries (LoLBins) are legitimate, pre-installed Windows tools that can be repurposed for malicious activities. Using these tools is effective for evasion because they are signed by Microsoft and are often whitelisted by security policies. Certutil, Mshta, and Regsvr32 are classic examples that can fetch remote files or execute scripts while appearing as normal system operations.

Exam trap

Candidates often include tools like 'mimikatz.exe' or 'netcat.exe'. These are not LoLBins because they are not signed, native Windows binaries. Stick to Microsoft-signed tools.

7
Multi-Selectmedium

Which TWO methods are effective for obfuscating a PowerShell script to bypass AMSI without modifying the underlying system DLLs?

Select 2 answers
A.String Concatenation
B.Memory Patching
C.Variable Randomization
D.Registry Modification
E.Kernel Driver Loading
AnswersA, C

By breaking a keyword like 'amsiInitFailed' into smaller pieces (e.g., 'am' + 'si' + 'Init') and joining them at runtime, the static scanner cannot see the full word. Since AMSI often relies on keyword-based signatures, this simple technique can effectively prevent the script from being flagged during the pre-execution scan.

Why this answer

PowerShell obfuscation for AMSI bypass focuses on making the script content unrecognizable to the scanner. String concatenation breaks up known malicious keywords, while variable randomization ensures that simple signature matches fail. These techniques are applied directly to the script code and do not require administrative privileges to patch memory or modify protected system files like amsi.dll.

Exam trap

Candidates often guess 'patching amsi.dll in memory'. The question specifically asks for methods to obfuscate the script content itself, not methods that modify the system's memory-resident AMSI engine.

8
MCQeasy

A junior penetration tester is preparing a payload for a Windows 10 target and wants to avoid signature-based detection by changing the binary's appearance without altering its functionality. Which technique is specifically designed to achieve this?

A.Splitting the payload into multiple chunks and reassembling at runtime.
B.Running the payload from a remote SMB share instead of the local disk.
C.Encoding the payload with msfvenom's shikata_ga_nai encoder multiple times.
D.Compressing the payload with UPX to reduce its size.
AnswerC

Shikata_ga_nai is an encoder that transforms the payload's bytes using a polymorphic XOR additive feedback loop, changing the binary appearance while preserving functionality. Applying it multiple times further mutates the signature, which can help evade static signature-based detection. This is a classic PEN-200 technique for altering the file's binary appearance without changing what the payload does.

Why this answer

Shikata_ga_nai is a polymorphic encoder that mutates the payload's bytes while preserving its functionality, directly targeting signature-based detection by changing the binary appearance. The other options either do not alter the binary signature, are easily unpacked, or change only the delivery mechanism rather than the payload's bytes.

Exam trap

The trap here is assuming that packing or splitting a payload changes its signature, when those methods either get unpacked by AV or leave the original bytes intact.

9
MCQmedium

An operator is analyzing why a compiled C# stager payload was flagged immediately by Windows Defender despite having a completely unique cryptographic hash. Which AV detection mechanism is most likely responsible for flagging the binary based on internal structure rather than known file signatures?

A.Cloud-based cryptographic hash lookup databases containing global blacklists of known malware samples.
B.Static signature matching using rigid byte sequences extracted from older malware variants.
C.Heuristic analysis evaluating suspicious API imports, section characteristics, and code patterns indicative of stagers.
D.Network signature inspection monitoring incoming HTTP traffic headers for default command and control strings.
AnswerC

Heuristic analysis analyzes the structural makeup of an executable, including imported DLLs like VirtualAlloc and CreateThread. When these suspicious API combinations appear together in an unknown binary, the engine flags it as a potential threat based on risk scoring.

Why this answer

Heuristic and behavioral engines examine internal characteristics, structural layouts, and API import patterns rather than relying strictly on known file hashes. If a binary imports suspicious combinations of memory allocation and execution APIs, heuristics flag it as malicious even if the file has never been seen before.

Exam trap

Many beginners believe that changing a file hash via padding guarantees evasion, ignoring that structural heuristics and API imports are heavily analyzed.

10
MCQmedium

During a PEN-200 lab engagement, a tester delivers a custom C# implant compiled with csc.exe. Windows Defender's real-time protection immediately quarantines the executable at rest on disk, before any process is created. The tester wants to keep the same implant logic but reduce static file-based detection. Which approach best addresses this specific detection stage?

A.Rename the executable to a trusted Windows binary name such as svchost.exe and place it in C:\Windows\System32.
B.Pack the executable with a custom crypter that XOR-encrypts the payload bytes and decrypts them only in memory at runtime.
C.Compress the executable into a password-protected ZIP archive and deliver the archive to the target host.
D.Sign the executable with a self-signed code-signing certificate generated with makecert.exe.
AnswerB

Static on-disk scanning matches byte signatures and PE characteristics before execution. A crypter that XOR-encrypts the original payload bytes and only reconstructs them in memory changes the stored file's byte pattern, so the signature that flagged the plaintext implant no longer matches the file on disk. The implant logic still runs after decryption, satisfying the requirement to preserve behavior while reducing file-based detection.

Why this answer

Detection at rest is driven by static signatures over the file's bytes and PE structure. Changing the stored representation so the original signature no longer matches, while reconstructing the functional payload only in memory, directly defeats that stage. Renaming, self-signing, and archiving leave the underlying executable bytes unchanged, so the same on-disk signature continues to match once the file is written or extracted.

Exam trap

The trap here is assuming that renaming or signing a binary changes what static scanners inspect, when they actually match the file's byte content and PE structure.

11
MCQeasy

When evaluating an antivirus solution's effectiveness, what is the primary difference between signature-based detection and behavioral-based detection?

A.Signatures look for file hashes, while behavior looks for network traffic.
B.Signatures identify known files, while behavior identifies suspicious actions.
C.Signatures are only used for disk scans, while behavior is for memory scans.
D.Behavioral detection is always more accurate and faster than signature-based.
AnswerB

Signature detection compares a file's content against a list of known malware 'fingerprints.' Behavioral detection, on the other hand, monitors the actual operations a program performs while running, such as attempting to inject code into another process or modifying sensitive registry keys, allowing it to catch zero-day threats.

Why this answer

Signature-based detection is a reactive approach that relies on a database of known threats, while behavioral-based detection is a proactive approach that monitors for suspicious actions. Understanding this distinction is crucial for evasion, as bypassing one often requires different techniques than bypassing the other, such as obfuscating file content versus using legitimate system tools for malicious purposes.

Exam trap

Candidates often equate 'behavioral' with 'heuristic'. While related, the core distinction is between static file-based signatures versus runtime activity monitoring of legitimate processes.

12
MCQmedium

An ethical hacker wants to evade signature-based detection while developing a custom reverse shell loader for a PEN-200 lab assignment. Which technique fundamentally alters the binary's byte signatures without modifying its core execution logic or breaking the payload?

A.Stripping all debugging symbols and symbol tables from the executable using strip.
B.Modifying the file extension from .exe to .scr to trick the operating system shell.
C.Applying XOR encoding to the payload buffer and implementing a custom runtime stub to decrypt it in memory.
D.Compressing the final executable binary using standard ZIP archiving utilities without a password.
AnswerC

XOR encoding modifies every byte of the payload based on a key, entirely changing the static file hashes and byte signatures. A custom runtime stub allocates memory, decrypts the payload on the fly, and executes it without ever writing the cleartext binary back to disk.

Why this answer

Encoding or encrypting the payload alters static byte signatures that antivirus engines use to flag known malicious files. By decoding the payload dynamically in memory at runtime, the payload remains obfuscated on disk, preventing signature detection while preserving the exact execution logic required for the reverse shell to successfully connect back to the attacking machine.

Exam trap

Candidates often confuse static encryption with process injection, assuming that hiding the payload on disk automatically bypasses behavioral monitoring during runtime execution.

13
MCQhard

Refer to the exhibit. An examiner attempts to use raw msfvenom output directly in a custom C template for a PEN-200 lab assignment, but the payload is instantly detected. Why is generating raw msfvenom output generally ineffective for antivirus evasion without further modification?

A.The C array output format automatically introduces formatting syntax errors that cause the compiler to generate invalid portable executable headers.
B.Default msfvenom payloads contain heavily signatured stager stubs and byte patterns that are universally fingerprinted by security products.
C.Using HTTPS as the communication protocol forces the stager to include unencrypted TLS certificates that antivirus software automatically blocks.
D.The 64-bit architecture flag conflicts with standard Windows Defender file scanning routines, triggering an immediate administrative alert.
AnswerB

Raw msfvenom output embeds the default Meterpreter stager stub, whose fixed byte sequences and shellcode patterns are catalogued by antivirus vendors. Detection therefore occurs on signature alone, before any behavioural analysis, so custom encoding or obfuscation is required.

Why this answer

Default msfvenom templates and encoders contain heavily signatured instruction patterns and well-known strings that antivirus vendors have fingerprinted extensively over many years. Without custom encoding, manual structural modifications, or custom loader implementation, raw framework outputs are immediately flagged by signature scanners.

Exam trap

Candidates often assume that changing output formats from raw bytes to a C array somehow modifies the underlying signature, whereas the actual bad byte sequences remain completely unchanged.

14
MCQeasy

A junior penetration tester is preparing a payload for a Windows 10 target with Windows Defender enabled. The tester wants to avoid writing the payload to disk and decides to use a PowerShell one-liner that downloads and executes a script in memory. Which PowerShell feature allows the script to be executed directly from a downloaded string without saving it to a file?

A.Add-Type with a downloaded assembly.
B.Invoke-Expression (IEX) with a downloaded string.
C.Start-Process with the -FilePath parameter pointing to a URL.
D.Import-Module with a URL to a .psm1 file.
AnswerB

Invoke-Expression evaluates a string as PowerShell code in the current session. When combined with a download cradle such as (New-Object Net.WebClient).DownloadString('http://...'), the script is fetched into memory and executed immediately, leaving no file on disk. This is a common in-memory execution technique that helps evade file-based detection, though AMSI may still inspect the script content at runtime.

Why this answer

Invoke-Expression takes a string and runs it as PowerShell code. By pairing it with a download cradle, the tester can retrieve a script into memory and execute it without touching disk. This is a standard in-memory execution technique for PowerShell.

The other cmdlets either do not execute arbitrary PowerShell code, require local files, or are intended for different purposes such as loading .NET types or modules, so they do not fulfill the requirement.

Exam trap

The trap here is confusing cmdlets that can download content with those that can execute PowerShell code directly from a string, such as assuming Start-Process or Import-Module can run a script from a URL.

15
MCQmedium

A penetration tester has written a C# loader that reads shellcode from a file, allocates memory with VirtualAlloc using PAGE_EXECUTE_READWRITE, and executes it via CreateThread. The loader is not detected by static antivirus signatures, but when run on a Windows 10 host with Microsoft Defender's real-time protection enabled, the process is terminated shortly after execution begins. The tester suspects behavior-based detection. Which modification is MOST likely to prevent this behavioral detection while preserving execution?

A.Replace VirtualAlloc with VirtualAllocEx and allocate memory in a remote process.
B.Encrypt the shellcode with AES and decrypt it at runtime using a hardcoded key.
C.Add a call to Sleep with a random delay before executing the shellcode.
D.Use separate VirtualAlloc calls with PAGE_READWRITE then VirtualProtect to PAGE_EXECUTE_READ before execution.
AnswerD

Allocating memory as RWX is a strong indicator of malicious behavior. By first allocating with PAGE_READWRITE, writing the shellcode, and then changing the protection to PAGE_EXECUTE_READ via VirtualProtect, the loader avoids leaving an RWX region, which many behavioral engines flag. This technique is a common evasion step and preserves local execution without introducing remote process operations.

Why this answer

The loader is being flagged behaviorally because it allocates memory with both write and execute permissions (RWX), a pattern rarely seen in legitimate software. Separating allocation and execution by using PAGE_READWRITE followed by VirtualProtect to PAGE_EXECUTE_READ removes the RWX indicator while still allowing shellcode execution. Other options either do not change the behavioral footprint or introduce additional suspicious activity.

Exam trap

The trap here is assuming that encrypting the shellcode or adding a delay will bypass behavioral detection, when the real trigger is the RWX memory allocation pattern.

16
Multi-Selectmedium

A penetration tester is building a custom shellcode runner in C for a PEN-200 lab. The compiled loader is being flagged by static analysis before execution. The tester wants to modify the loader's source so the resulting binary is less likely to match signatures, without changing the shellcode's behavior. Which two changes best serve this goal? (Choose two.)

Select 2 answers
A.Statically link the C runtime library so the loader has fewer external dependencies.
B.Add a large embedded PNG image resource to increase the binary's file size.
C.Encrypt the embedded shellcode with a simple XOR key and decrypt it in memory before execution.
D.Compile the loader with the /O2 optimization flag to reduce the binary's overall size.
E.Replace direct API calls with dynamically resolved function pointers using LoadLibrary and GetProcAddress.
AnswersC, E

Embedded plaintext shellcode is a strong static indicator because its bytes match known signatures. Storing the shellcode XOR-encrypted and decrypting it at runtime removes those recognizable bytes from the on-disk binary, so signatures targeting the shellcode no longer match. Behavior is preserved because the decrypted buffer is what executes, making this a direct way to reduce static detection while keeping functionality.

Why this answer

Static analysis of the loader is driven by recognizable shellcode bytes and a suspicious import table. XOR-encrypting the shellcode removes its signature-matching bytes from disk, and resolving APIs dynamically with LoadLibrary and GetProcAddress removes telltale imports like VirtualAlloc and VirtualProtect. Optimization, static runtime linking, and padding change size or dependencies but leave the shellcode bytes and imported APIs that triggered detection in place.

Exam trap

The trap here is treating size or dependency changes as evasion, when static signatures key on the shellcode bytes and the import table rather than the binary's overall footprint.

17
MCQhard

During a red team engagement, a tester writes a C# loader that calls the Win32 API function VirtualAllocEx to allocate memory in a remote process, writes shellcode, and creates a remote thread. The loader compiles and runs, but the endpoint's EDR blocks it before the remote thread executes. The tester confirms the EDR is hooking user-mode API functions in ntdll.dll. Which approach most directly avoids the user-mode hooks that triggered the block?

A.Add the /DYNAMICBASE:NO linker flag so the loader's base address does not change between runs.
B.Replace the calls to VirtualAllocEx and CreateRemoteThread with their NtAllocateVirtualMemory and NtCreateThreadEx equivalents from ntdll.dll.
C.Call VirtualProtect on the ntdll.dll .text section to restore the original bytes before invoking the API.
D.Implement direct system calls by reading the syscall numbers from a clean copy of ntdll.dll and executing the syscall instruction directly from the loader's own code.
AnswerD

EDR user-mode hooks live in the ntdll.dll code that the loader would normally call. By extracting the syscall service numbers and issuing the syscall instruction from the loader's own memory, the execution never passes through the hooked ntdll stubs. The kernel still performs the operation, but the EDR's user-mode interception point is skipped. This directly addresses the described hooking mechanism.

Why this answer

User-mode EDR hooks are implemented by patching the entry points of functions inside ntdll.dll. Any call that goes through those functions, whether via the kernel32 wrapper or the Nt-prefixed export, passes through the hook. Direct system calls sidestep the problem by placing the syscall instruction in the loader's own code with the correct service number, so execution transitions to kernel mode without touching the hooked ntdll stubs.

This is the most reliable way to bypass user-mode hooking without altering system DLLs.

Exam trap

The trap here is thinking that calling the lower-level Nt function instead of the Win32 wrapper avoids EDR hooks, when in fact the hooks are placed inside ntdll.dll where those Nt functions reside.

18
MCQmedium

A penetration tester has obtained a low-privilege shell on a Windows 10 host protected by Windows Defender with real-time protection enabled. The tester wants to execute a custom .NET assembly in memory to avoid writing a payload to disk, but Defender's AMSI integration repeatedly flags the assembly when loaded via the standard reflection technique. Which modification to the in-memory loading approach is MOST likely to prevent AMSI from inspecting the assembly's content?

A.Base64-encode the assembly bytes and load them with Assembly.LoadFrom after decoding.
B.Patch the AmsiScanBuffer function in amsi.dll in the current process before loading the assembly.
C.Store the assembly on a remote SMB share and load it with Assembly.LoadFrom over the network path.
D.Encrypt the assembly with AES and decrypt it directly into a memory region allocated with PAGE_EXECUTE_READWRITE.
AnswerB

AMSI ultimately routes assembly and script content through AmsiScanBuffer in amsi.dll. By overwriting the function prologue in the current process with a stub that returns a clean result, the tester prevents Defender from receiving the buffer for inspection. This is a classic runtime AMSI bypass that works for .NET assembly loads because the CLR calls into AMSI via that same exported function. It does not require disabling Defender globally.

Why this answer

AMSI integrates with the .NET runtime and submits assembly content to AmsiScanBuffer before execution. Patching that function in the current process causes the scan to return a benign result, allowing the in-memory assembly to load without Defender receiving the buffer. Encryption, encoding, and remote loading do not prevent the runtime from passing the decrypted or fetched bytes to AMSI, so they fail against runtime inspection even though they may help against static file signatures.

Exam trap

The trap here is assuming that encrypting or encoding the payload hides it from AMSI, when AMSI inspects the decrypted buffer at the moment the runtime submits it for scanning.

19
MCQmedium

A penetration tester delivers a custom .NET executable to a Windows 10 host running Microsoft Defender with cloud-delivered protection enabled. The binary contains an embedded shellcode blob in its .data section. After the loader decrypts the shellcode in memory and begins executing it, Defender terminates the process even though the file itself never touched disk again. Which technique would most directly address this specific detection?

A.Base64-encode the shellcode and decode it immediately before calling CreateThread.
B.Change the shellcode's allocation from VirtualAlloc with PAGE_EXECUTE_READWRITE to VirtualAlloc with PAGE_READWRITE, then use VirtualProtect to flip the page to PAGE_EXECUTE_READ just before invoking the shellcode.
C.Encrypt the shellcode with XOR and decrypt it at runtime using a stack-based routine.
D.Recompile the loader with the /GS- flag to disable stack cookies and reduce the binary's static footprint.
AnswerB

Defender's behavioral engine commonly flags a single allocation that is simultaneously writable and executable, since legitimate code rarely needs RWX pages. Allocating as RW, writing the decrypted shellcode, then flipping to RX via VirtualProtect mimics how a normal loader maps code and removes the RWX indicator. The shellcode still executes, but the high-signal memory characteristic that triggered termination is eliminated.

Why this answer

The detection is behavioral and memory-resident, so the fix must change how memory is allocated and protected. Marking a single region both writable and executable is a classic high-signal indicator that Defender's behavioral engine correlates with shellcode loaders. Allocating writable, writing the payload, and then re-protecting the page as executable removes that indicator while still allowing the shellcode to run.

Encoding, compiler flags, and static obfuscation do not affect the in-memory execution profile.

Exam trap

The trap here is assuming that any obfuscation of the shellcode bytes will defeat Defender, when the detection is triggered by the memory protection state at execution time rather than the file contents.

20
MCQmedium

An analyst is attempting to execute a custom C2 stager on a Windows 10 workstation with active Windows Defender. They decide to use a PowerShell one-liner that downloads a script from a remote server and executes it directly using the Invoke-Expression (IEX) cmdlet. Why is this method generally more effective than downloading an .exe file to the Desktop?

A.It bypasses the Antimalware Scan Interface (AMSI) entirely by default.
B.Memory-only execution avoids the file-on-disk signature scanning process.
C.PowerShell scripts are automatically trusted by the Windows integrity system.
D.The method uses the System.Net.WebClient class which encrypts the payload.
AnswerB

Antivirus software heavily relies on scanning new files created on the hard drive against a database of known malware signatures. By executing code directly in memory using Invoke-Expression, the payload never triggers the file system write hooks that would normally prompt an immediate scan, allowing the code to run if it can evade behavioral analysis.

Why this answer

In-memory execution avoids the creation of files on the physical disk, which is where most traditional antivirus solutions perform their primary signature-based scanning. By keeping the malicious payload within the volatile memory of the PowerShell process, the attacker minimizes the forensic footprint and reduces the likelihood of triggering alerts associated with suspicious file creation or modification events on the local file system.

Exam trap

Candidates frequently focus on file-based obfuscation, ignoring that simply writing a suspicious .exe to disk triggers immediate signature scanning, whereas memory-only execution bypasses this specific detection layer entirely.

21
Multi-Selecthard

A penetration tester needs to deliver a Meterpreter payload to a Windows target protected by an EDR that performs both static file scanning and behavioral monitoring of process creation. The tester wants to reduce the chance of detection during initial execution while still obtaining a session. Which two techniques most directly reduce detection in this combined scenario? (Choose two.)

Select 2 answers
A.Disable Windows Defender real-time protection by modifying the registry before executing the payload.
B.Rename the payload executable to svchost.exe and place it in the user's temp directory.
C.Spawn the payload by injecting into a legitimate, already-running process such as explorer.exe rather than starting a new process.
D.Compress the payload with UPX and deliver it as a self-extracting archive.
E.Use a custom loader that stores the shellcode encrypted and decrypts it into memory only at runtime.
AnswersC, E

EDR behavioral monitoring often flags the creation of a new, unsigned process that immediately performs suspicious actions. Injecting into an existing trusted process like explorer.exe avoids a new process creation event and places the malicious code inside a process the EDR considers benign. This directly addresses the behavioral monitoring component described in the scenario.

Why this answer

The scenario involves two distinct controls: static file scanning and behavioral process monitoring. A custom loader with encrypted shellcode removes recognizable bytes from disk, defeating static signatures. Injecting into an existing trusted process avoids the new-process creation event that behavioral engines monitor, placing execution inside a process already deemed legitimate.

Together these address both controls. Renaming, UPX packing, and registry tampering either leave the static bytes intact or generate their own high-signal events.

Exam trap

The trap here is treating static obfuscation and behavioral evasion as interchangeable, when the scenario explicitly includes both controls and requires a technique that addresses each one separately.

22
MCQmedium

Refer to the exhibit. [!] Error compiling payload: Function 'VirtualAlloc' not found in target assembly scope. An operator is writing a custom process injection loader in C# and encounters the compilation error shown above while attempting to allocate memory for shellcode. How should the operator properly resolve this issue to enable low-level memory allocation?

A.Replace VirtualAlloc with the standard .NET File.ReadAllBytes method to read the shellcode into a byte array.
B.Enable unsafe code blocks in the project settings and use raw C-style pointer arithmetic directly.
C.Import the unmanaged function from kernel32.dll using Platform Invoke (P/Invoke) declarations.
D.Compile the C# application as a 64-bit exclusive binary to match the target operating system architecture.
AnswerC

Importing VirtualAlloc from kernel32.dll via P/Invoke declarations supplies the missing unmanaged Win32 API that the .NET runtime cannot expose natively, resolving the compile error. This satisfies the stem's requirement for low-level memory allocation, since managed C# has no built-in equivalent for reserving executable pages.

Why this answer

Managed languages like C# do not natively expose low-level Windows API functions like VirtualAlloc without explicit interoperability declarations. Utilizing Platform Invoke allows developers to import unmanaged DLL functions from kernel32.dll, bridging the gap between managed code execution and low-level memory manipulation required for advanced payload execution.

Exam trap

Candidates often assume managed C# code can natively call native Win32 APIs like VirtualAlloc directly without realizing that low-level memory allocation requires explicit unmanaged interoperability declarations via P/Invoke.

23
Multi-Selectmedium

Which TWO techniques are primarily used to bypass static signature-based detection by altering the file's binary appearance without changing its underlying functionality?

Select 2 answers
A.Binary Packing
B.Process Hollowing
C.Payload Encryption
D.Direct System Calls
E.Token Manipulation
AnswersA, C

Packing involves using a tool to compress and wrap the original executable within a new outer layer. When the file is scanned on disk, the antivirus only sees the packer's code rather than the malicious payload. At runtime, the packer decompress the original code into memory, effectively hiding the malware from static analysis.

Why this answer

Static evasion focuses on changing the 'look' of the file to bypass signature databases. Packing compresses the executable and adds a wrapper that unpacks it in memory, while encryption hides the payload entirely until runtime. Both techniques drastically change the file's hash and byte sequence, making it unrecognizable to scanners that rely on matching known malicious code patterns on disk.

Exam trap

Candidates often confuse static evasion with dynamic evasion, focusing on changing code behavior rather than altering the binary's appearance to bypass the signature-based detection databases used by antivirus software.

24
Multi-Selecthard

When evaluating antivirus evasion techniques for Windows targets in a penetration test, which TWO of the following approaches specifically target memory-based detection mechanisms rather than static disk signatures? (Choose TWO)

Select 2 answers
A.Direct system calls invoked via assembly instructions to bypass user-mode hooks placed by security software in ntdll.dll.
B.Applying a multi-layer XOR encoder to obfuscate the binary payload before writing the executable to the target hard drive.
C.Process injection into a legitimate native Windows process such as explorer.exe to mask malicious execution threads.
D.Modifying the compilation timestamp within the portable executable header to confuse static signature heuristics.
E.Compressing the compiled binary with UPX to scramble sections and alter the import address table layout.
AnswersA, C

Security solutions place inline hooks within user-mode DLLs like ntdll.dll to monitor API calls. Implementing direct system calls bypasses these hooked functions entirely, allowing the payload to interact directly with the kernel without triggering user-mode security monitoring alerts.

Why this answer

Memory-based evasion techniques focus on how payloads behave in RAM and interact with operating system APIs. Syscall manipulation avoids hooked functions in ntdll.dll, while process injection executes code within legitimate, trusted processes to blend in with normal system activity and avoid heuristic flags.

Exam trap

Students frequently select static packing or XOR encoding, forgetting that those techniques only apply to files stored on the filesystem and offer zero protection once the process starts running.

25
MCQmedium

An attacker places a malicious 'version.dll' file into the same directory as a legitimate, signed executable that is known to load that DLL. When the legitimate program starts, it loads the malicious DLL instead of the one in the System32 folder. What evasion technique is being demonstrated?

A.DLL Injection
B.DLL Sideloading
C.COM Hijacking
D.Reflective DLL Loading
AnswerB

Sideloading takes advantage of the Windows DLL search order, which prioritizes the application's directory over system directories. By naming the malicious file after a required dependency, the attacker tricks a trusted application into executing their code. This is a highly effective way to gain execution while appearing as a legitimate, signed process.

Why this answer

DLL Sideloading exploits the default search order that Windows uses to locate dynamic-link libraries. By placing a malicious DLL in the application's local directory, the attacker ensures it is loaded before the legitimate system DLL. This allows malicious code to run under the context of a trusted, signed process, which often bypasses security controls and behavioral alerts.

Exam trap

Candidates often confuse DLL Sideloading with DLL Hijacking or Search Order Hijacking. While related, Sideloading specifically refers to placing a malicious DLL alongside a legitimate executable to exploit the default search order.

26
Multi-Selecthard

Which THREE techniques are commonly implemented in malware to detect and evade dynamic analysis within an automated sandbox environment?

Select 3 answers
A.Checking for a low number of CPU cores or small RAM size
B.Executing a large number of NOP instructions to increase file size
C.Monitoring for specific mouse movements or keyboard input
D.Implementing long 'Sleep' delays or complex timing loops
E.Using direct syscalls to bypass the Windows API hooks
AnswersA, C, D

Automated sandboxes are often resource-constrained to save costs, frequently operating with only one or two CPU cores and minimal memory. Legitimate modern workstations typically have more resources. Malware can check these hardware specifications and terminate execution if they fall below a certain threshold, assuming the environment is a virtualized analysis lab.

Why this answer

Sandbox evasion relies on identifying traits that distinguish a virtualized, automated analysis environment from a real user workstation. Malware often checks for specific hardware configurations, waits for human-like interaction, or uses long delays to exceed the sandbox's limited analysis time. These methods ensure the malicious payload remains dormant while the environment is being monitored by security researchers.

Exam trap

Candidates frequently select 'checking for network connectivity' or 'checking for domain membership'. While relevant, these are not the most common core sandbox evasion techniques requested in standard exam scenarios.

27
MCQeasy

A penetration tester is preparing a Windows payload for a client engagement where the target endpoint runs a traditional signature-based antivirus product that does not perform cloud lookups. The tester wants to reduce the chance that the raw output of msfvenom is flagged during initial delivery. Which action best addresses this goal?

A.Rename the payload file to a benign-looking name such as invoice.pdf.exe and set the archive attribute.
B.Compile a custom loader that embeds the shellcode in an encrypted form and decrypts it at runtime, rather than delivering the raw msfvenom executable.
C.Use msfvenom's -e encoder option with shikata_ga_nai and iterate the encoding multiple times.
D.Pipe the msfvenom output through gzip and deliver the compressed archive to the target.
AnswerB

A custom loader with encrypted embedded shellcode presents a different on-disk artifact than the original msfvenom executable, so the signature that matched the raw payload no longer applies. The executable's own code is unique to the tester, and the shellcode is not present in a recognizable form until runtime decryption. This directly addresses signature-based detection at delivery without relying on well-known encoders.

Why this answer

Signature-based antivirus matches known byte patterns in files. To avoid that match, the delivered artifact must not contain those known patterns. Building a custom loader that stores shellcode in encrypted form produces a file whose bytes differ entirely from the raw msfvenom output, so the original signature no longer applies.

Compression and renaming leave the executable bytes intact, and well-known encoders like shikata_ga_nai are themselves signatured.

Exam trap

The trap here is believing that compressing, renaming, or re-encoding a payload hides it from signature scanning, when the scanner reads the underlying executable bytes regardless of wrapper or filename.

28
MCQhard

A penetration tester uses process hollowing to hide their payload inside 'svchost.exe'. They start the process in a suspended state, unmap its memory, write their shellcode, and resume the thread. What is a specific indicator that an advanced EDR might use to detect this activity?

A.The 'svchost.exe' process will show a significantly higher CPU usage.
B.The entry point of the process in memory differs from the image on disk.
C.The process will be unable to communicate with the network.
D.The system will automatically restart the process due to a checksum error.
AnswerB

EDR tools can compare the executable's entry point and memory map against the original file on disk. When a process is hollowed, the memory contents and the entry point are modified to point to the malicious code. This mismatch is a clear sign that the process has been tampered with and is no longer legitimate.

Why this answer

Process hollowing is a powerful evasion technique, but it leaves behind traces in the system's memory and process metadata. Advanced EDR solutions monitor for discrepancies between the file on disk and the code in memory. They also track specific API call sequences, such as creating a process in a suspended state followed immediately by memory unmapping and cross-process writing.

Exam trap

Candidates often suggest 'the process is running as SYSTEM'. While true, EDRs look for specific memory-based indicators, not just process privileges.

29
MCQeasy

A tester is preparing a reverse shell executable for a Windows target protected by a signature-based antivirus product. To reduce the chance the file is flagged, the tester wants to modify the binary so it no longer matches known signatures while keeping its behavior. Which action best accomplishes this?

A.Run the executable with administrator privileges so it can bypass user-level scanning hooks.
B.Move the executable from the Downloads folder to a less commonly scanned directory such as C:\Temp.
C.Change the file's icon and version information resource to mimic a legitimate application.
D.Recompile the source after renaming functions and adding benign junk instructions, then rebuild the binary.
AnswerD

Static signatures often include byte sequences from compiled code, strings, and payload data. Renaming functions and inserting junk instructions alters the compiled output's byte layout and instruction sequence while preserving the program's logic. Rebuilding produces a new binary whose bytes no longer match the original signature, which directly addresses signature matching without changing behavior, matching the tester's stated goal.

Why this answer

Signature-based detection compares file bytes against known patterns derived from code, strings, and embedded payloads. Altering the source so the compiled binary's byte sequence changes, such as renaming functions and inserting junk instructions, breaks that match while preserving functionality. Metadata edits, directory changes, and privilege elevation leave the underlying bytes intact, so the original signature continues to identify the file.

Exam trap

The trap here is believing that cosmetic metadata like icons or version strings, or the file's location, affects content-based signature matching when scanners examine the executable's bytes.

30
MCQmedium

During a PEN-200 lab, a penetration tester develops a custom C# loader that allocates memory, writes shellcode, and executes it. Windows Defender's AMSI flags the process when the shellcode buffer is passed to a scanning routine. The tester wants to prevent AMSI from inspecting the buffer at runtime without disabling Defender. Which technique should the tester apply?

A.Use the AmsiScanBuffer function's memory patching to force it to return a clean result.
B.Run the loader under a different user account with limited privileges.
C.Base64-encode the shellcode and decode it at runtime before execution.
D.Compile the loader with the /guard:cf flag to enable Control Flow Guard.
AnswerA

Patching AmsiScanBuffer in memory (e.g., by overwriting its first bytes with a return value of S_OK or a benign HRESULT) prevents AMSI from scanning the buffer, effectively bypassing detection without disabling Defender. This is a common in-memory evasion technique taught in PEN-200 for evading AMSI.

Why this answer

AMSI scans buffers passed to functions like AmsiScanBuffer; to evade it without disabling Defender, the tester can patch AmsiScanBuffer in memory to return a benign result. This prevents the shellcode from being flagged. Encoding, CFG, or user privileges do not stop AMSI from scanning the buffer at runtime.

Exam trap

The trap here is assuming that encoding or obfuscating shellcode prevents AMSI from scanning it, when AMSI actually inspects the decoded buffer in memory.

31
MCQmedium

A penetration tester has a working PowerShell-based stager that is being blocked by AMSI on a Windows 11 target. The tester wants to keep using PowerShell for convenience but needs the stager to run without AMSI inspecting the script content. Which technique most directly targets AMSI's inspection of the script?

A.Set the PowerShell execution policy to Bypass using the -ExecutionPolicy Bypass parameter.
B.Sign the PowerShell script with a trusted code-signing certificate before execution.
C.Obfuscate the stager and split it across multiple string concatenations and variable substitutions so the script text does not contain recognizable AMSI signatures.
D.Run the stager through a PowerShell downgrade to version 2 using the -Version 2 parameter.
AnswerC

AMSI scans the script content as it is submitted for execution, matching known malicious patterns. If the script is rewritten so that no contiguous string matches an AMSI signature, the scan passes and the script executes. Techniques such as string splitting, character substitution, and dynamic construction change the textual representation while preserving behavior. This directly targets AMSI's pattern-matching inspection of the script.

Why this answer

AMSI inspects PowerShell script content by matching patterns against known malicious code. If the script text no longer contains those patterns, the inspection passes. Obfuscation through string splitting, concatenation, and dynamic construction changes the textual form while preserving the executed logic, so the stager runs.

Execution policy and code signing are separate controls, and version downgrade is unreliable on patched Windows 11 systems where AMSI enforcement is not tied to the PowerShell version.

Exam trap

The trap here is assuming that bypassing execution policy or using an older PowerShell version will also bypass AMSI, when AMSI inspects script content independently of those controls.

32
MCQhard

During an authorized penetration test, a tester needs to deliver a Meterpreter payload to a Windows Server 2019 target that runs a next-generation antivirus with behavioral monitoring. The tester decides to use a process injection technique to run the payload inside a legitimate process. Which injection method is LEAST likely to be flagged by behavioral monitoring because it avoids allocating new executable memory in the target process?

A.Process hollowing by creating a suspended process and replacing its image.
B.Thread execution hijacking by suspending a thread and modifying its context to point to shellcode.
C.Classic CreateRemoteThread with VirtualAllocEx and WriteProcessMemory.
D.Module stomping by overwriting the .text section of a loaded DLL with shellcode.
AnswerD

Module stomping writes shellcode into the existing executable .text section of a legitimately loaded DLL, so no new executable memory is allocated. Because the memory is already marked executable and belongs to a signed module, behavioral monitors that focus on new executable allocations or thread creation may not flag it. This technique is stealthier against memory-permission-based detection, though integrity checks on the DLL could still reveal tampering.

Why this answer

Module stomping avoids allocating new executable memory by reusing the existing .text section of a loaded DLL. Since the memory is already executable and associated with a legitimate module, it bypasses detection logic that looks for new PAGE_EXECUTE_READWRITE allocations or suspicious thread creation. Other injection methods require allocating or modifying executable memory in ways that behavioral monitoring commonly correlates with malicious activity, making them more likely to be flagged.

Exam trap

The trap here is assuming that any injection method that avoids CreateRemoteThread is automatically stealthy, when most still allocate new executable memory that behavioral monitoring watches for.

33
MCQhard

A penetration tester has a working unmanaged PowerShell runner in C# that executes a script block on a Windows 10 host with AMSI enabled. The runner currently fails because AMSI scans the script content. The tester wants to disable AMSI scanning for the current process without touching files on disk and without requiring administrative privileges. Which technique best fits these constraints?

A.Set the registry value HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableAMSI to 1.
B.Run the PowerShell runner from a session launched with the -NoProfile and -ExecutionPolicy Bypass switches.
C.Patch the AmsiScanBuffer function in memory by overwriting its first bytes with a return value that indicates a clean scan.
D.Delete the amsi.dll file from C:\Windows\System32 and reboot the target host.
AnswerC

AMSI resolves AmsiScanBuffer from amsi.dll inside each process. Overwriting the function's prologue in the current process's memory so it returns a benign result causes subsequent scans to report no detection, and this works within the user's own process without admin rights or disk changes. It matches the requirement to disable scanning for the current process only and leaves files untouched.

Why this answer

AMSI performs in-process scanning through functions resolved from amsi.dll, most notably AmsiScanBuffer. Because the DLL is loaded into the calling process, a user-mode patch of that function in memory changes scan results for that process only, needs no administrative rights, and writes nothing to disk. Deleting system files, inventing registry policies, or adjusting execution policy do not alter the in-memory scanning path AMSI uses.

Exam trap

The trap here is confusing PowerShell's execution policy, which governs script running, with AMSI, which performs content scanning independent of that policy.

34
Multi-Selectmedium

A penetration tester is preparing to bypass antivirus on a Windows target during a PEN-200 lab. The tester wants to use packing and encryption to alter the payload's signature and avoid static detection. Which TWO techniques are effective for evading static signature-based detection by changing the file's binary appearance without altering its functionality? (Choose two.)

Select 2 answers
A.Modifying the PE header to change the compile timestamp and checksum.
B.Renaming the executable file to a system process name such as svchost.exe.
C.Encrypting the payload with a unique key and including the decryption routine in a custom loader.
D.Using a packer that compresses and encrypts the original executable, with a stub that decrypts it in memory at runtime.
E.Appending random bytes to the end of the executable to change its file hash.
AnswersC, D

Encrypting the payload with a unique key ensures that the on-disk bytes are different for each build, defeating static signatures that rely on fixed byte patterns. The custom loader decrypts the payload in memory before execution, so functionality is preserved. This is a strong method for evading static detection because the encrypted payload does not match known signatures. It requires the loader to handle decryption and execution, often leading to in-memory execution.

Why this answer

Effective static evasion requires changing the bytes that signatures match. Packers encrypt and compress the original code, so the on-disk file no longer contains the recognizable pattern. Encrypting the payload with a unique key and a custom loader achieves the same by making each build's bytes unique.

Both preserve functionality while altering the binary appearance. Appending random bytes, renaming, or modifying PE metadata do not change the core code sections that signatures target, so they are ineffective for evading static detection.

Exam trap

The trap here is thinking that any change to the file, such as appending bytes or renaming, will evade signature detection, when only changes that alter the actual code or data patterns are effective.

Ready to test yourself?

Try a timed practice session using only Antivirus Evasion questions.