Courseiva
Antivirus Evasion →mediumMultiple Select

PEN-200 Antivirus Evasion Practice Question

Which TWO techniques are primarily used to bypass static signature-based detection by altering the file's binary appearance without changing its underlying functionality?

⚠ Common exam trap

Candidates often confuse static evasion with dynamic evasion, focusing on changing code behavior rather than altering the binary's appearance to bypass the signature-based detection databases used by antivirus software.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Binary Packing

Static evasion focuses on changing the 'look' of the file to bypass signature databases. Packing compresses the executable and adds a wrapper that unpacks it in memory, while encryption hides the payload entirely until runtime. Both techniques drastically change the file's hash and byte sequence, making it unrecognizable to scanners that rely on matching known malicious code patterns on disk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Binary Packing

    Why this is correct

    Packing involves using a tool to compress and wrap the original executable within a new outer layer. When the file is scanned on disk, the antivirus only sees the packer's code rather than the malicious payload. At runtime, the packer decompress the original code into memory, effectively hiding the malware from static analysis.

  • ✗

    Process Hollowing

    Why it's wrong here

    Process hollowing is a dynamic evasion technique used to hide the execution of malicious code within a legitimate process's memory space. While it helps evade detection during runtime, it is not a method for altering the static appearance of a file on disk before it is executed, which is the focus of signature-based bypass.

  • ✓

    Payload Encryption

    Why this is correct

    Encrypting the payload ensures that the actual malicious instructions are not visible to static scanners. A small stub of code is included to decrypt the payload in memory at runtime. Since the encrypted data appears as random noise to the scanner, it cannot match any known signatures, effectively bypassing most static detection mechanisms.

  • ✗

    Direct System Calls

    Why it's wrong here

    Using direct system calls is a technique designed to bypass EDR hooks and API monitoring during execution. It involves manually invoking kernel functions instead of using standard Windows API libraries. This is a dynamic evasion strategy aimed at bypassing behavioral monitoring rather than changing the static signature or binary appearance of the file on disk.

  • ✗

    Token Manipulation

    Why it's wrong here

    Token manipulation is a post-exploitation technique used for privilege escalation or impersonation by stealing and applying access tokens from other processes. It does not involve changing the binary structure or appearance of a file to bypass antivirus signatures, making it irrelevant to the goal of evading static detection during the initial delivery.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.