PEN-200 Antivirus Evasion Practice Question
Why is using the default 'msfvenom' encoders like 'shikata_ga_nai' often insufficient for bypassing modern antivirus solutions?
⚠ Common exam trap
Candidates mistakenly believe msfvenom encoders are security features. They are functional tools for payload delivery, and their signatures are widely known by AV engines.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The decoding stubs have well-known, static signatures.
Metasploit encoders were originally designed to remove 'bad characters' from shellcode to ensure it would run correctly in an exploit. They were not primarily intended for antivirus evasion. Because these encoders are open-source and widely used, antivirus vendors have had years to develop highly accurate signatures for the decoding stubs they generate, making them easily detectable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
They only work on 32-bit systems and are ignored by 64-bit AV.
Why it's wrong here
While some encoders are architecture-specific, this is not the reason they are insufficient for evasion. There are 64-bit versions of many encoders. The issue is not the architecture, but rather the fact that the logic and patterns used by these encoders are well-known and easily recognized by security software on any architecture.
- ✗
The encoders increase the file size, making it look suspicious.
Why it's wrong here
While encoding does slightly increase the size of the shellcode, the increase is usually negligible (a few hundred bytes). Antivirus software does not flag files solely because they are slightly larger than expected. The detection is based on the recognizable patterns within the code, specifically the decoding loop that precedes the payload.
- ✓
The decoding stubs have well-known, static signatures.
Why this is correct
Antivirus vendors include the signatures for common Metasploit encoder stubs in their databases. Even though the payload itself is 'randomized' by the encoder, the small piece of code that decrypts that payload remains recognizable. Since this stub must run first, the antivirus identifies it immediately and blocks the execution before the payload is even unpacked.
- ✗
They use encryption that is easily decrypted by the AV engine.
Why it's wrong here
The issue is not whether the AV can decrypt the payload, but rather that it recognizes the tool used to hide it. Most AV engines don't even bother decrypting the payload; they simply flag the file as malicious based on the presence of the known 'shikata_ga_nai' decoder stub, which is enough to confirm the file's intent.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.