Courseiva
Antivirus Evasion →mediumMultiple Choice

PEN-200 Antivirus Evasion Practice Question

During a PEN-200 lab engagement, a tester delivers a custom C# implant compiled with csc.exe. Windows Defender's real-time protection immediately quarantines the executable at rest on disk, before any process is created. The tester wants to keep the same implant logic but reduce static file-based detection. Which approach best addresses this specific detection stage?

⚠ Common exam trap

The trap here is assuming that renaming or signing a binary changes what static scanners inspect, when they actually match the file's byte content and PE structure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pack the executable with a custom crypter that XOR-encrypts the payload bytes and decrypts them only in memory at runtime.

Detection at rest is driven by static signatures over the file's bytes and PE structure. Changing the stored representation so the original signature no longer matches, while reconstructing the functional payload only in memory, directly defeats that stage. Renaming, self-signing, and archiving leave the underlying executable bytes unchanged, so the same on-disk signature continues to match once the file is written or extracted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rename the executable to a trusted Windows binary name such as svchost.exe and place it in C:\Windows\System32.

    Why it's wrong here

    Renaming a file does not alter its contents, so any signature matching the PE body still fires regardless of filename. Placing it in System32 may also trigger additional protection because Defender watches system directories closely, and writing there typically requires elevated privileges. This does nothing to change the byte pattern that caused the on-disk quarantine, so the same detection recurs.

  • ✓

    Pack the executable with a custom crypter that XOR-encrypts the payload bytes and decrypts them only in memory at runtime.

    Why this is correct

    Static on-disk scanning matches byte signatures and PE characteristics before execution. A crypter that XOR-encrypts the original payload bytes and only reconstructs them in memory changes the stored file's byte pattern, so the signature that flagged the plaintext implant no longer matches the file on disk. The implant logic still runs after decryption, satisfying the requirement to preserve behavior while reducing file-based detection.

  • ✗

    Compress the executable into a password-protected ZIP archive and deliver the archive to the target host.

    Why it's wrong here

    Password-protected archives are commonly used to bypass email gateway scanning in transit, not to defeat on-disk AV. Once the tester extracts the executable to run it, the plaintext PE is written back to disk and Defender scans it at that point. The archive only delays detection; it does not change the executable's byte pattern that the static signature matches.

  • ✗

    Sign the executable with a self-signed code-signing certificate generated with makecert.exe.

    Why it's wrong here

    A self-signed certificate is not chained to a trusted root, so Windows and Defender treat it as untrusted and gain no reputation benefit. Signing changes only the certificate table appended to the PE, leaving the code section and its signature intact. The original byte pattern that triggered quarantine remains present, so static detection still matches the file on disk.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.