PEN-200 Antivirus Evasion Practice Question
When analyzing the memory of a compromised system, you find that your shellcode is being detected by behavioral monitoring. What is the most effective approach to reduce the likelihood of detection by EDR systems during process injection?
⚠ Common exam trap
Candidates frequently confuse direct API calls with evasion techniques, assuming standard process injection methods are stealthy enough to bypass modern EDR behavioral monitoring without modifications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Utilizing indirect syscalls to execute memory operations without triggering API hooks.
Behavioral detection focuses on suspicious API calls, such as VirtualAllocEx and WriteProcessMemory, being called by an unauthorized or unexpected process. By using indirect syscalls or alternative memory allocation methods, you can bypass the hooks that security products place on high-level Windows APIs. This is critical in modern testing because EDRs monitor process interactions in real-time, making standard injection techniques trivial for security software to identify and block immediately.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increasing the sleep interval between shellcode execution stages.
Why it's wrong here
While sleep intervals can help evade simple timer-based sandboxes, they do not hide the malicious nature of the API calls being made. EDR solutions monitor the memory manipulation sequence itself, and simply delaying the execution does not change the fundamental behavior that triggers the security alert.
- ✓
Utilizing indirect syscalls to execute memory operations without triggering API hooks.
Why this is correct
Indirect syscalls bypass the user-mode hooks installed by EDRs in common Windows APIs like NtAllocateVirtualMemory. By invoking the kernel directly from the assembly, the shellcode avoids passing through monitored functions, effectively blinding the EDR to the memory allocation process, which is the primary indicator of malicious injection.
- ✗
Injecting the shellcode into a low-privilege process to minimize impact.
Why it's wrong here
The privilege level of the target process does not prevent EDR behavioral monitoring. Regardless of user rights, the EDR monitors memory access patterns and cross-process interactions. Injecting into a low-privilege process might avoid some local security policy restrictions, but it remains fully visible to the EDR's instrumentation.
- ✗
Replacing the shellcode with an equivalent set of PowerShell commands.
Why it's wrong here
PowerShell is heavily monitored by modern security products through Antimalware Scan Interface (AMSI). Using PowerShell commands for injection is often more detectable than native machine code, as every command can be inspected in real-time by the engine before execution, leading to near-instant identification and blocking.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.