PEN-200 Antivirus Evasion Practice Question
During an authorized penetration test, a tester needs to deliver a Meterpreter payload to a Windows Server 2019 target that runs a next-generation antivirus with behavioral monitoring. The tester decides to use a process injection technique to run the payload inside a legitimate process. Which injection method is LEAST likely to be flagged by behavioral monitoring because it avoids allocating new executable memory in the target process?
⚠ Common exam trap
The trap here is assuming that any injection method that avoids CreateRemoteThread is automatically stealthy, when most still allocate new executable memory that behavioral monitoring watches for.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Module stomping by overwriting the .text section of a loaded DLL with shellcode.
Module stomping avoids allocating new executable memory by reusing the existing .text section of a loaded DLL. Since the memory is already executable and associated with a legitimate module, it bypasses detection logic that looks for new PAGE_EXECUTE_READWRITE allocations or suspicious thread creation. Other injection methods require allocating or modifying executable memory in ways that behavioral monitoring commonly correlates with malicious activity, making them more likely to be flagged.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Process hollowing by creating a suspended process and replacing its image.
Why it's wrong here
Process hollowing creates a new process in a suspended state, unmaps its original image, and writes a malicious image in its place. This involves allocating executable memory and modifying the process image, which behavioral monitoring can detect through image mapping anomalies and suspicious memory permissions. Although it can evade static detection, the hollowing sequence is a known indicator that many EDR solutions monitor for.
- ✗
Thread execution hijacking by suspending a thread and modifying its context to point to shellcode.
Why it's wrong here
Thread execution hijacking still requires placing shellcode somewhere in the target process, often via VirtualAllocEx and WriteProcessMemory, and then redirecting the thread's instruction pointer. The act of allocating executable memory and altering a thread context is suspicious and commonly flagged. It avoids creating a new thread, but the memory allocation and context change remain strong behavioral indicators for EDR.
- ✗
Classic CreateRemoteThread with VirtualAllocEx and WriteProcessMemory.
Why it's wrong here
This classic technique allocates new memory with PAGE_EXECUTE_READWRITE in the remote process and writes the payload there, then starts a thread. Behavioral monitors commonly flag the combination of remote memory allocation with executable permissions and a new thread creation, because it is a well-known injection pattern. While it may work against some AVs, it is highly visible to modern EDR that correlates these API calls.
- ✓
Module stomping by overwriting the .text section of a loaded DLL with shellcode.
Why this is correct
Module stomping writes shellcode into the existing executable .text section of a legitimately loaded DLL, so no new executable memory is allocated. Because the memory is already marked executable and belongs to a signed module, behavioral monitors that focus on new executable allocations or thread creation may not flag it. This technique is stealthier against memory-permission-based detection, though integrity checks on the DLL could still reveal tampering.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.