CEH Practice Question: Malware, Social Engineering and Network Attacks
An analyst is analyzing a suspicious file using VirusTotal and observes that only 3 out of 60 antivirus engines detect it as malicious. The file has been submitted before but with no detections. What should the analyst conclude?
⚠ Common exam trap
EC-Council often tests the misconception that a low detection rate (e.g., 3/60) means the file is safe, when in fact it indicates the file is likely malicious and requires further investigation, especially if the detection count has increased from zero.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The file is likely malicious and requires further analysis
A detection rate of 3 out of 60 (5%) is extremely low, but the fact that the file was previously submitted with zero detections and now has three detections indicates that the antivirus engines have updated their signatures to identify it. This pattern is consistent with a new or polymorphic malware strain that initially evaded detection but is now being recognized by a few engines. A low detection rate does not guarantee safety; it often signals a targeted or zero-day threat that requires further analysis through sandboxing or dynamic analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The file is a clean file with a rare hash
Why it's wrong here
A rare hash explains low prevalence, not three engines independently identifying malicious code; clean files do not acquire detections between submissions. Calling it clean is tempting because most engines report nothing, yet the newly appearing detections indicate the file is malicious, not merely uncommon.
- ✗
The file is safe because most engines don't detect it
Why it's wrong here
Antivirus coverage varies by engine, so three detections still constitute positive identification; absence of majority detection does not establish safety. Trusting the majority is tempting given VirusTotal's aggregate score, but the file's changed status from zero detections indicates malware that evades most signatures.
- ✗
The file is likely a false positive
Why it's wrong here
Three engines flagging a file that previously scored zero indicates new signatures or heuristics now catch it, which points to malware rather than a false positive; false positives typically show consistent detections across many engines. Concluding false positive is tempting when detections are sparse, but the changed verdict signals genuine threat.
- ✓
The file is likely malicious and requires further analysis
Why this is correct
Low detection counts do not prove benignity; three engines flagging the file indicates likely maliciousness. The earlier zero-detection submission suggests a new or modified variant evading signatures, so the analyst should treat it as suspicious and perform deeper dynamic and static analysis.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.