Courseiva
Antivirus Evasion →hardMultiple Select

PEN-200 Antivirus Evasion Practice Question

Which THREE techniques are commonly implemented in malware to detect and evade dynamic analysis within an automated sandbox environment?

⚠ Common exam trap

Candidates frequently select 'checking for network connectivity' or 'checking for domain membership'. While relevant, these are not the most common core sandbox evasion techniques requested in standard exam scenarios.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Checking for a low number of CPU cores or small RAM size

Sandbox evasion relies on identifying traits that distinguish a virtualized, automated analysis environment from a real user workstation. Malware often checks for specific hardware configurations, waits for human-like interaction, or uses long delays to exceed the sandbox's limited analysis time. These methods ensure the malicious payload remains dormant while the environment is being monitored by security researchers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Checking for a low number of CPU cores or small RAM size

    Why this is correct

    Automated sandboxes are often resource-constrained to save costs, frequently operating with only one or two CPU cores and minimal memory. Legitimate modern workstations typically have more resources. Malware can check these hardware specifications and terminate execution if they fall below a certain threshold, assuming the environment is a virtualized analysis lab.

  • ✗

    Executing a large number of NOP instructions to increase file size

    Why it's wrong here

    Adding NOP instructions is a static evasion technique used to change a file's signature or offset code blocks. It does not help in detecting a sandbox environment during runtime. While it might slightly delay execution, it is not a reliable or primary method for identifying whether the code is running in a virtualized analysis tool.

  • ✓

    Monitoring for specific mouse movements or keyboard input

    Why this is correct

    Sandboxes are automated and often lack human interaction. Malware can record the mouse coordinates over time or wait for a specific number of clicks before detonating. If no movement is detected, the malware assumes it is being analyzed by an automated system and remains inactive to avoid revealing its true malicious capabilities.

  • ✓

    Implementing long 'Sleep' delays or complex timing loops

    Why this is correct

    Most sandboxes only analyze a file for a few minutes before moving to the next task. By calling a sleep function for an extended period, such as ten minutes, the malware can outlast the analysis window. When the sandbox times out and reports the file as benign, the malware can then safely execute its payload.

  • ✗

    Using direct syscalls to bypass the Windows API hooks

    Why it's wrong here

    While direct syscalls are used to evade EDR and sandbox monitoring of API calls, they are a method of bypassing the 'hooks' rather than detecting the sandbox itself. This technique allows the malware to function while being watched, whereas sandbox evasion aims to prevent the malware from functioning at all until it is safe.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.