Courseiva
Antivirus Evasion →easyMultiple Choice

PEN-200 Antivirus Evasion Practice Question

Why is using the default 'msfvenom' encoders like 'shikata_ga_nai' often insufficient for bypassing modern antivirus solutions?

⚠ Common exam trap

Candidates mistakenly believe msfvenom encoders are security features. They are functional tools for payload delivery, and their signatures are widely known by AV engines.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The decoding stubs have well-known, static signatures.

Metasploit encoders were originally designed to remove 'bad characters' from shellcode to ensure it would run correctly in an exploit. They were not primarily intended for antivirus evasion. Because these encoders are open-source and widely used, antivirus vendors have had years to develop highly accurate signatures for the decoding stubs they generate, making them easily detectable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    They only work on 32-bit systems and are ignored by 64-bit AV.

    Why it's wrong here

    While some encoders are architecture-specific, this is not the reason they are insufficient for evasion. There are 64-bit versions of many encoders. The issue is not the architecture, but rather the fact that the logic and patterns used by these encoders are well-known and easily recognized by security software on any architecture.

  • ✗

    The encoders increase the file size, making it look suspicious.

    Why it's wrong here

    While encoding does slightly increase the size of the shellcode, the increase is usually negligible (a few hundred bytes). Antivirus software does not flag files solely because they are slightly larger than expected. The detection is based on the recognizable patterns within the code, specifically the decoding loop that precedes the payload.

  • ✓

    The decoding stubs have well-known, static signatures.

    Why this is correct

    Antivirus vendors include the signatures for common Metasploit encoder stubs in their databases. Even though the payload itself is 'randomized' by the encoder, the small piece of code that decrypts that payload remains recognizable. Since this stub must run first, the antivirus identifies it immediately and blocks the execution before the payload is even unpacked.

  • ✗

    They use encryption that is easily decrypted by the AV engine.

    Why it's wrong here

    The issue is not whether the AV can decrypt the payload, but rather that it recognizes the tool used to hide it. Most AV engines don't even bother decrypting the payload; they simply flag the file as malicious based on the presence of the known 'shikata_ga_nai' decoder stub, which is enough to confirm the file's intent.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.