nerdexam
GIAC

GPEN · Question #187

You have received a file named new.com in your email as an attachment. When you execute this file in your laptop, you get the following message: 'EICAR-STANDARD-ANTIVIRUS-TEST-FILE!' When you open…

The correct answer is B. Do nothing. The EICAR Standard Anti-Virus Test File is a completely harmless, internationally recognized test string used solely to verify antivirus detection - it contains no malicious payload.

Penetration Testing Foundations & Reconnaissance

Question

You have received a file named new.com in your email as an attachment. When you execute this file in your laptop, you get the following message:

'EICAR-STANDARD-ANTIVIRUS-TEST-FILE!' When you open the file in Notepad, you get the following string:

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* What step will you take as a countermeasure against this attack?

Options

  • AImmediately shut down your laptop.
  • BDo nothing.
  • CTraverse to all of your drives, search new.com files, and delete them.
  • DClean up your laptop with antivirus.

How the community answered

(23 responses)
  • A
    9% (2)
  • B
    70% (16)
  • C
    17% (4)
  • D
    4% (1)

Why each option

The EICAR Standard Anti-Virus Test File is a completely harmless, internationally recognized test string used solely to verify antivirus detection - it contains no malicious payload.

AImmediately shut down your laptop.

Shutting down the laptop is an unnecessary and disruptive overreaction - the EICAR file contains no executable malicious code and cannot damage the system or spread.

BDo nothing.Correct

The string X5O!P%@AP[4\PZX54(P^)7CC)7}}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* is the official EICAR test file defined by the European Institute for Computer Antivirus Research specifically to allow safe testing of antivirus software without using real malware. It causes no harm, makes no system changes, and requires no remediation because it is not malicious in any way.

CTraverse to all of your drives, search new.com files, and delete them.

Searching for and deleting all new.com files is unwarranted because the EICAR file is a benign, standardized test artifact and not actual malware that needs to be eradicated.

DClean up your laptop with antivirus.

Running an antivirus cleanup is unnecessary because the EICAR file is intentionally detectable by antivirus programs as a test pattern - any detection is a sign the AV is working correctly, not that the system is infected.

Concept tested: EICAR standard antivirus test file recognition

Source: https://www.eicar.org/download-anti-malware-testfile/

Topics

#EICAR test file#antivirus testing#malware identification#false positive

Community Discussion

No community discussion yet for this question.

Full GPEN Practice