Courseiva
Antivirus Evasion →mediumMultiple Select

PEN-200 Antivirus Evasion Practice Question

Which THREE 'Living off the Land' (LotL) binaries are frequently used by penetration testers to download or execute malicious code while bypassing basic antivirus restrictions?

⚠ Common exam trap

Candidates often include tools like 'mimikatz.exe' or 'netcat.exe'. These are not LoLBins because they are not signed, native Windows binaries. Stick to Microsoft-signed tools.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

certutil.exe

Living off the Land binaries (LoLBins) are legitimate, pre-installed Windows tools that can be repurposed for malicious activities. Using these tools is effective for evasion because they are signed by Microsoft and are often whitelisted by security policies. Certutil, Mshta, and Regsvr32 are classic examples that can fetch remote files or execute scripts while appearing as normal system operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    certutil.exe

    Why this is correct

    Certutil is a command-line program for managing certificates, but it includes a '-urlcache -split -f' parameter that allows it to download files from the internet. Because it is a trusted system utility, many basic antivirus programs and firewall rules do not flag it when it initiates a network connection to retrieve a file.

  • ✓

    mshta.exe

    Why this is correct

    Mshta is responsible for executing HTML Applications (.hta). It can be used to run malicious JavaScript or VBScript directly from a remote URL or a local file. Since mshta.exe is a signed Microsoft binary, it can often bypass execution restrictions and is a common choice for initial access and payload delivery.

  • ✓

    regsvr32.exe

    Why this is correct

    Regsvr32 is a command-line utility used to register and unregister DLLs. By using the '/s /n /u /i' flags along with a URL pointing to a scrobj.dll (SCT) file, an attacker can execute arbitrary script code in memory. This 'Squiblydoo' attack is a well-known method for bypassing application whitelisting and antivirus.

  • ✗

    calc.exe

    Why it's wrong here

    While 'calc.exe' is often used as a proof-of-concept to show successful code execution, the calculator itself does not have built-in functionality to download or execute external code. It is a simple utility with no network or scripting capabilities, making it useless as a tool for delivering or staging a malicious payload.

  • ✗

    notepad.exe

    Why it's wrong here

    Notepad is a basic text editor and lacks any features that would allow it to download files or execute scripts. While it can be used to view malicious code, it cannot be 'lived off the land' to facilitate the execution or delivery of a payload in the same way that tools like mshta or certutil can.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.