Courseiva

PEN-200 · topic practice

Antivirus Evasion practice questions

This domain covers evading Windows Defender, AMSI, and EDR during payload delivery and execution. You must build and modify custom C# and PowerShell loaders, understand how static signatures, AMSI scanning, and behavioral process-creation monitoring detect shellcode, and apply obfuscation, encryption, and API-resolution techniques to reduce detection on target hosts.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Antivirus Evasion

What the exam tests

What to know about Antivirus Evasion

You must write, compile, and troubleshoot custom C# and PowerShell loaders that inject shellcode while evading Defender and AMSI. The single most important thing is verifying API declarations and obfuscating or encrypting both the payload and the loader so neither static nor AMSI scanning flags them.

Compiling C# loaders that resolve Win32 APIs like VirtualAlloc, VirtualAllocEx, and CreateRemoteThread correctly

Understanding AMSI scanning of PowerShell and .NET buffers and how to bypass or obfuscate content

Using encryption, encoding, and in-memory execution to defeat static file signatures in Windows Defender

Reducing behavioral detection of process injection and remote thread creation monitored by EDR products

Watch out for

Common Antivirus Evasion exam traps

  • ▸Declaring P/Invoke signatures incorrectly or omitting the required namespace, causing errors like 'VirtualAlloc not found in target assembly scope'
  • ▸Assuming a compiled loader is undetected without testing against current Defender signatures and AMSI
  • ▸Encrypting shellcode but leaving the decryption routine or plaintext buffer exposed to AMSI or memory scanning

Practice set

Antivirus Evasion questions

20 questions · select your answer, then reveal the explanation

An advanced evasion tool uses direct system calls (Syscalls) by extracting the syscall numbers from ntdll.dll and executing them using assembly. What is the primary advantage of this approach over using standard Windows API functions like NTWriteVirtualMemory?

An ethical hacker is developing a custom C# loader to bypass Windows Defender on an engagement. The analyst notices that a simple reverse shell payload containing clear strings like 'cmd.exe' is immediately flagged on disk. Which technique is most effective for obfuscating these critical strings within the binary to prevent static signature detection?

During an assessment, a penetration tester attempts to execute a staged Meterpreter payload via PowerShell, but AMSI (Antisimalware Scan Interface) blocks the script execution. Which TWO techniques can the tester employ to bypass or disable AMSI inspection effectively within the PowerShell session?

You are attempting to deliver a custom payload to a target machine protected by signature-based antivirus. Despite obfuscating the payload, the AV continues to flag the binary on disk. Which technique is most effective at preventing the AV from performing static analysis on the file structure?

You are preparing a payload for a Windows environment with AMSI enabled. Which TWO of the following strategies are most effective at evading AMSI-based detection during the execution of script-based payloads?

A penetration tester has obtained a Meterpreter shell on a Windows 10 host with Windows Defender active. The tester wants to upload and execute a known malicious tool without triggering Defender's real-time protection. Which evasion technique is most appropriate to achieve this?

During a PEN-200 lab, you deliver a custom C# implant to a Windows 10 host running Microsoft Defender with cloud-delivered protection enabled. The implant uses direct P/Invoke to VirtualAlloc, CreateThread, and WaitForSingleObject. The payload executes successfully on your machine but is quarantined on the target before any callback is observed. Which single change is most likely to prevent quarantine while preserving the implant's behavior?

A tester needs to deliver a payload to a Windows 10 target where outbound HTTP and HTTPS are inspected, and the tester wants to avoid writing the payload to disk. The tester plans to use a PowerShell download cradle to fetch and execute the payload directly in memory. Which combination of commands best achieves in-memory execution without touching disk?

A penetration tester is developing a custom C# loader to execute a shellcode payload on a Windows target with an EDR solution that monitors for suspicious API calls. The tester wants to avoid using the commonly flagged combination of VirtualAlloc with PAGE_EXECUTE_READWRITE and CreateThread. Which alternative memory allocation and execution strategy is MOST effective at reducing the loader's behavioral footprint?

A penetration tester is preparing a payload for a Windows 10 target with Windows Defender real-time protection enabled. The tester wants to evade detection by leveraging trusted, signed Microsoft binaries rather than writing custom code. Which TWO techniques are most appropriate for this goal? (Choose two.)

A penetration tester has gained a foothold on a Windows 10 host with Windows Defender and wants to execute a PowerShell-based reconnaissance script without triggering AMSI. The script contains strings such as 'Invoke-Mimikatz' and 'AmsiUtils'. Which technique is most effective for bypassing AMSI in this context?

Question 12mediummultiple choice
Read the full Antivirus Evasion explanation →

An analyst is attempting to execute a custom C2 stager on a Windows 10 workstation with active Windows Defender. They decide to use a PowerShell one-liner that downloads a script from a remote server and executes it directly using the Invoke-Expression (IEX) cmdlet. Why is this method generally more effective than downloading an .exe file to the Desktop?

A penetration tester modifies a known exploit's payload by changing variable names and adding junk instructions. Despite these changes, the antivirus software still flags the file as 'Trojan.Generic' immediately upon being written to disk. What is the most likely reason for this detection?

Which TWO techniques are primarily used to bypass static signature-based detection by altering the file's binary appearance without changing its underlying functionality?

Question 15mediummultiple choice
Read the full Antivirus Evasion explanation →

An attacker places a malicious 'version.dll' file into the same directory as a legitimate, signed executable that is known to load that DLL. When the legitimate program starts, it loads the malicious DLL instead of the one in the System32 folder. What evasion technique is being demonstrated?

Which THREE techniques are commonly implemented in malware to detect and evade dynamic analysis within an automated sandbox environment?

When evaluating an antivirus solution's effectiveness, what is the primary difference between signature-based detection and behavioral-based detection?

Which TWO methods are effective for obfuscating a PowerShell script to bypass AMSI without modifying the underlying system DLLs?

Question 19mediummultiple choice
Read the full Antivirus Evasion explanation →

A tester is targeting a Windows machine and notices that a specific legitimate application regularly looks for a COM object that is missing from the HKEY_CURRENT_USER (HKCU) registry hive, eventually falling back to HKEY_LOCAL_MACHINE (HKLM). How can this be exploited for evasion?

Which THREE 'Living off the Land' (LotL) binaries are frequently used by penetration testers to download or execute malicious code while bypassing basic antivirus restrictions?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Antivirus Evasion sessions

Start a Antivirus Evasion only practice session

Every question in these sessions is drawn from the Antivirus Evasion domain — nothing else.

Related practice questions

Related PEN-200 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PEN-200 exam test about Antivirus Evasion?
You must write, compile, and troubleshoot custom C# and PowerShell loaders that inject shellcode while evading Defender and AMSI. The single most important thing is verifying API declarations and obfuscating or encrypting both the payload and the loader so neither static nor AMSI scanning flags them.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Antivirus Evasion questions in a focused session?
Yes — the session launcher on this page draws every question from the Antivirus Evasion domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PEN-200 topics?
Use the topic links above to move to related areas, or go back to the PEN-200 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PEN-200 exam covers. They are not copied from any real exam or dump site.