ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During an email-focused penetration test, you need to confirm that the organization's secure mail gateway can detect and block known malware while eliminating any possibility of an actual infection. Which technique should you include in your test case?
Email a password-protected ZIP archive containing the latest Emotet sample to several employee inboxes.
Disable endpoint scanning on a spare workstation inside the LAN and execute a Zeus Trojan binary.
Email the EICAR standard anti-virus test file as an attachment and observe how the gateway handles it.
Spoof the gateway's update server to capture signature download traffic during the test window.
Including the EICAR standard anti-virus test file as an email attachment is the safest and most appropriate approach. The 68-byte text string is harmless but recognized by nearly all commercial anti-malware engines as a virus test signature, allowing you to exercise detection, quarantine, and alerting workflows without risking real infection. Transmitting live malware-even inside a password-protected ZIP-or executing a Trojan on an internal host violates safe-handling practices and can lead to uncontrolled spread. Spoofing the gateway's update server evaluates signature-retrieval integrity, not malware detection effectiveness. Therefore, the EICAR test file best meets the requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the EICAR standard anti-virus test file?
Open an interactive chat with Bash
Why is sending live malware in a password-protected ZIP unsafe?
Open an interactive chat with Bash
What does spoofing a gateway's update server evaluate?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .