PEN-200 Antivirus Evasion Practice Question
When evaluating antivirus evasion techniques for Windows targets in a penetration test, which TWO of the following approaches specifically target memory-based detection mechanisms rather than static disk signatures? (Choose TWO)
⚠ Common exam trap
Students frequently select static packing or XOR encoding, forgetting that those techniques only apply to files stored on the filesystem and offer zero protection once the process starts running.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Direct system calls invoked via assembly instructions to bypass user-mode hooks placed by security software in ntdll.dll.
Memory-based evasion techniques focus on how payloads behave in RAM and interact with operating system APIs. Syscall manipulation avoids hooked functions in ntdll.dll, while process injection executes code within legitimate, trusted processes to blend in with normal system activity and avoid heuristic flags.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Direct system calls invoked via assembly instructions to bypass user-mode hooks placed by security software in ntdll.dll.
Why this is correct
Security solutions place inline hooks within user-mode DLLs like ntdll.dll to monitor API calls. Implementing direct system calls bypasses these hooked functions entirely, allowing the payload to interact directly with the kernel without triggering user-mode security monitoring alerts.
- ✗
Applying a multi-layer XOR encoder to obfuscate the binary payload before writing the executable to the target hard drive.
Why it's wrong here
Applying an XOR encoder modifies the static appearance of the file on disk. However, once the encoded stub runs and decrypts the payload into memory, it must execute API calls that are actively monitored by the antivirus or EDR runtime sensors.
- ✓
Process injection into a legitimate native Windows process such as explorer.exe to mask malicious execution threads.
Why this is correct
Injecting into a legitimate native process such as explorer.exe hides malicious threads inside trusted memory space, evading behavioural and memory-scanning detection that inspects running processes rather than on-disk signatures. This directly satisfies the stem's requirement to target memory-based mechanisms instead of static disk signatures.
- ✗
Modifying the compilation timestamp within the portable executable header to confuse static signature heuristics.
Why it's wrong here
Altering the PE header timestamp modifies static metadata used by some heuristic engines to group similar malware variants. This change has no effect on runtime behavior, memory inspection, or API call monitoring performed by modern endpoint detection tools.
- ✗
Compressing the compiled binary with UPX to scramble sections and alter the import address table layout.
Why it's wrong here
UPX compression alters the binary layout and obscures the import address table on disk. While it successfully hides static signatures from basic scanners, advanced security solutions automatically unpack or emulate UPX-packed binaries during runtime analysis.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.