PEN-200 Antivirus Evasion Practice Question
Which THREE 'Living off the Land' (LotL) binaries are frequently used by penetration testers to download or execute malicious code while bypassing basic antivirus restrictions?
⚠ Common exam trap
Candidates often include tools like 'mimikatz.exe' or 'netcat.exe'. These are not LoLBins because they are not signed, native Windows binaries. Stick to Microsoft-signed tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
certutil.exe
Living off the Land binaries (LoLBins) are legitimate, pre-installed Windows tools that can be repurposed for malicious activities. Using these tools is effective for evasion because they are signed by Microsoft and are often whitelisted by security policies. Certutil, Mshta, and Regsvr32 are classic examples that can fetch remote files or execute scripts while appearing as normal system operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
certutil.exe
Why this is correct
Certutil is a command-line program for managing certificates, but it includes a '-urlcache -split -f' parameter that allows it to download files from the internet. Because it is a trusted system utility, many basic antivirus programs and firewall rules do not flag it when it initiates a network connection to retrieve a file.
- ✓
mshta.exe
Why this is correct
Mshta is responsible for executing HTML Applications (.hta). It can be used to run malicious JavaScript or VBScript directly from a remote URL or a local file. Since mshta.exe is a signed Microsoft binary, it can often bypass execution restrictions and is a common choice for initial access and payload delivery.
- ✓
regsvr32.exe
Why this is correct
Regsvr32 is a command-line utility used to register and unregister DLLs. By using the '/s /n /u /i' flags along with a URL pointing to a scrobj.dll (SCT) file, an attacker can execute arbitrary script code in memory. This 'Squiblydoo' attack is a well-known method for bypassing application whitelisting and antivirus.
- ✗
calc.exe
Why it's wrong here
While 'calc.exe' is often used as a proof-of-concept to show successful code execution, the calculator itself does not have built-in functionality to download or execute external code. It is a simple utility with no network or scripting capabilities, making it useless as a tool for delivering or staging a malicious payload.
- ✗
notepad.exe
Why it's wrong here
Notepad is a basic text editor and lacks any features that would allow it to download files or execute scripts. While it can be used to view malicious code, it cannot be 'lived off the land' to facilitate the execution or delivery of a payload in the same way that tools like mshta or certutil can.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.