Courseiva
Antivirus Evasion →mediumMultiple Select

PEN-200 Antivirus Evasion Practice Question

Which TWO methods are effective for obfuscating a PowerShell script to bypass AMSI without modifying the underlying system DLLs?

⚠ Common exam trap

Candidates often guess 'patching amsi.dll in memory'. The question specifically asks for methods to obfuscate the script content itself, not methods that modify the system's memory-resident AMSI engine.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

String Concatenation

PowerShell obfuscation for AMSI bypass focuses on making the script content unrecognizable to the scanner. String concatenation breaks up known malicious keywords, while variable randomization ensures that simple signature matches fail. These techniques are applied directly to the script code and do not require administrative privileges to patch memory or modify protected system files like amsi.dll.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    String Concatenation

    Why this is correct

    By breaking a keyword like 'amsiInitFailed' into smaller pieces (e.g., 'am' + 'si' + 'Init') and joining them at runtime, the static scanner cannot see the full word. Since AMSI often relies on keyword-based signatures, this simple technique can effectively prevent the script from being flagged during the pre-execution scan.

  • ✗

    Memory Patching

    Why it's wrong here

    Memory patching involves using P/Invoke to call Windows APIs like WriteProcessMemory to disable AMSI in the current process. While highly effective, this is a more advanced technique that involves interacting with the system's memory and DLLs, rather than just obfuscating the script content itself as specified in the question.

  • ✓

    Variable Randomization

    Why this is correct

    Replacing descriptive variable names with random alphanumeric strings makes the script much harder for both humans and automated signatures to analyze. If an antivirus signature is looking for a specific variable name commonly used in an exploit, this technique will bypass that signature by ensuring every instance of the script is unique.

  • ✗

    Registry Modification

    Why it's wrong here

    Modifying registry keys to disable security features like Windows Defender or Script Block Logging is a configuration-based evasion tactic. It does not involve obfuscating the script itself. Furthermore, modern Windows systems protect these registry keys, often requiring high-level privileges that an initial script execution might not yet possess.

  • ✗

    Kernel Driver Loading

    Why it's wrong here

    Loading a malicious kernel driver is a technique used to gain the highest level of system access and disable security tools from the kernel level. This is far beyond the scope of simple script obfuscation and requires significant privileges, making it unsuitable for the task of bypassing AMSI via script modifications.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.