Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

An analyst is analyzing a suspicious file using VirusTotal and observes that only 3 out of 60 antivirus engines detect it as malicious. The file has been submitted before but with no detections. What should the analyst conclude?

⚠ Common exam trap

EC-Council often tests the misconception that a low detection rate (e.g., 3/60) means the file is safe, when in fact it indicates the file is likely malicious and requires further investigation, especially if the detection count has increased from zero.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The file is likely malicious and requires further analysis

A detection rate of 3 out of 60 (5%) is extremely low, but the fact that the file was previously submitted with zero detections and now has three detections indicates that the antivirus engines have updated their signatures to identify it. This pattern is consistent with a new or polymorphic malware strain that initially evaded detection but is now being recognized by a few engines. A low detection rate does not guarantee safety; it often signals a targeted or zero-day threat that requires further analysis through sandboxing or dynamic analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The file is a clean file with a rare hash

    Why it's wrong here

    A rare hash explains low prevalence, not three engines independently identifying malicious code; clean files do not acquire detections between submissions. Calling it clean is tempting because most engines report nothing, yet the newly appearing detections indicate the file is malicious, not merely uncommon.

  • ✗

    The file is safe because most engines don't detect it

    Why it's wrong here

    Antivirus coverage varies by engine, so three detections still constitute positive identification; absence of majority detection does not establish safety. Trusting the majority is tempting given VirusTotal's aggregate score, but the file's changed status from zero detections indicates malware that evades most signatures.

  • ✗

    The file is likely a false positive

    Why it's wrong here

    Three engines flagging a file that previously scored zero indicates new signatures or heuristics now catch it, which points to malware rather than a false positive; false positives typically show consistent detections across many engines. Concluding false positive is tempting when detections are sparse, but the changed verdict signals genuine threat.

  • ✓

    The file is likely malicious and requires further analysis

    Why this is correct

    Low detection counts do not prove benignity; three engines flagging the file indicates likely maliciousness. The earlier zero-detection submission suggests a new or modified variant evading signatures, so the analyst should treat it as suspicious and perform deeper dynamic and static analysis.

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.