PEN-200 Antivirus Evasion Practice Question
Which TWO methods are effective for obfuscating a PowerShell script to bypass AMSI without modifying the underlying system DLLs?
⚠ Common exam trap
Candidates often guess 'patching amsi.dll in memory'. The question specifically asks for methods to obfuscate the script content itself, not methods that modify the system's memory-resident AMSI engine.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
String Concatenation
PowerShell obfuscation for AMSI bypass focuses on making the script content unrecognizable to the scanner. String concatenation breaks up known malicious keywords, while variable randomization ensures that simple signature matches fail. These techniques are applied directly to the script code and do not require administrative privileges to patch memory or modify protected system files like amsi.dll.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
String Concatenation
Why this is correct
By breaking a keyword like 'amsiInitFailed' into smaller pieces (e.g., 'am' + 'si' + 'Init') and joining them at runtime, the static scanner cannot see the full word. Since AMSI often relies on keyword-based signatures, this simple technique can effectively prevent the script from being flagged during the pre-execution scan.
- ✗
Memory Patching
Why it's wrong here
Memory patching involves using P/Invoke to call Windows APIs like WriteProcessMemory to disable AMSI in the current process. While highly effective, this is a more advanced technique that involves interacting with the system's memory and DLLs, rather than just obfuscating the script content itself as specified in the question.
- ✓
Variable Randomization
Why this is correct
Replacing descriptive variable names with random alphanumeric strings makes the script much harder for both humans and automated signatures to analyze. If an antivirus signature is looking for a specific variable name commonly used in an exploit, this technique will bypass that signature by ensuring every instance of the script is unique.
- ✗
Registry Modification
Why it's wrong here
Modifying registry keys to disable security features like Windows Defender or Script Block Logging is a configuration-based evasion tactic. It does not involve obfuscating the script itself. Furthermore, modern Windows systems protect these registry keys, often requiring high-level privileges that an initial script execution might not yet possess.
- ✗
Kernel Driver Loading
Why it's wrong here
Loading a malicious kernel driver is a technique used to gain the highest level of system access and disable security tools from the kernel level. This is far beyond the scope of simple script obfuscation and requires significant privileges, making it unsuitable for the task of bypassing AMSI via script modifications.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.