PEN-200 Antivirus Evasion Practice Question
You are tasked with delivering a Meterpreter payload to a Windows Server 2019 target protected by a next-generation antivirus that performs userland API hooking on NtAllocateVirtualMemory and NtProtectVirtualMemory. Your current C loader uses these APIs directly and is detected. Which technique is most appropriate to bypass the userland hooks without requiring kernel-level privileges?
⚠ Common exam trap
The trap here is believing that in-memory compilation or payload encryption changes the API call path, when both still invoke the hooked ntdll functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Direct system calls by manually constructing the syscall stub and invoking the syscall instruction.
Direct system calls bypass userland API hooks because the hooks are placed in ntdll's exported functions, and invoking the syscall instruction directly skips that code. The other options either require kernel privileges, still transit the hooked APIs, or only address static detection rather than the behavioral hooks causing the detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install a kernel-mode driver to remove the hooks from ntdll and restore original bytes.
Why it's wrong here
Installing a kernel-mode driver requires administrative privileges and typically a signed driver, which is not available in a standard PEN-200 lab scenario and would itself be a high-risk action. While kernel drivers can unhook ntdll, this approach is impractical for typical engagements and exceeds the scope of userland evasion. The question specifically asks for a technique that does not require kernel-level privileges.
- ✗
Encrypt the payload with AES and decrypt it in memory just before execution.
Why it's wrong here
Encrypting the payload addresses static signature detection of the shellcode bytes, not the hooked API calls. The loader must still call NtAllocateVirtualMemory and NtProtectVirtualMemory to place and execute the decrypted payload, and those calls will be intercepted by the AV's userland hooks. Encryption alone does not bypass the behavioral monitoring that flagged the loader.
- ✓
Direct system calls by manually constructing the syscall stub and invoking the syscall instruction.
Why this is correct
Manually building the syscall stub bypasses userland hooks because the hook resides in ntdll's exported function, not in the kernel transition path. By placing the syscall number in EAX and executing the syscall instruction directly, the loader skips the modified ntdll code entirely. This works without kernel privileges and is a standard PEN-200 technique for evading EDR hooks on memory allocation and protection APIs.
- ✗
Use PowerShell's Add-Type to compile the loader in memory, relying on the .NET runtime to bypass native hooks.
Why it's wrong here
Add-Type still ultimately calls the same native APIs through the CLR's P/Invoke layer, so the userland hooks on NtAllocateVirtualMemory and NtProtectVirtualMemory remain in the call path. The CLR does not provide a separate unhooked path to these functions. This technique may change the static signature but does not circumvent the behavioral hooks that triggered detection.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.