Prove on-access scanning works, then show what an exclusion lets through

short · 40 min · Objective 3.4

Task

Install an antivirus engine on lin-srv, prove it detects the EICAR test file both on demand and on access, then add a folder exclusion of the kind database servers need and show that the same file placed there is not detected. Exclusions are necessary; this lab shows exactly what each one costs.

Steps

  1. Update the signatures with freshclam while briefly connected, then return lin-srv to the isolated network.
  2. Create /srv/incoming and /srv/dbdata. Copy the EICAR test string from the EICAR organisation's website into a file /srv/incoming/eicar-test.txt by hand.
  3. Run clamscan -r /srv/incoming and save the output to lab/av/on-demand.txt.
  4. With on-access scanning enabled for /srv, create the same file again and save the matching clamonacc or clamd log lines to lab/av/on-access.txt.
  5. Add /srv/dbdata as an on-access exclusion (OnAccessExcludePath /srv/dbdata in clamd.conf), restart the scanner, and create the test file in /srv/dbdata. Save any log output, or its absence, to lab/av/excluded.txt, and the configuration line to lab/av/exclusion.txt.
  6. Record in lab/av/exclusions-policy.txt the three rules you would apply to every exclusion on a production server.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

grep -Eic 'Eicar.*FOUND|Infected files: [1-9]' lab/av/on-demand.txt
grep -Eic 'eicar.*FOUND' lab/av/on-access.txt
grep -Eic 'eicar.*FOUND' lab/av/excluded.txt
grep -c '/srv/dbdata' lab/av/exclusion.txt
grep -Eic 'narrow|document|review|specific' lab/av/exclusions-policy.txt

The on-demand scan found the test file and the on-access scanner logged it, and the excluded folder produced no detection -- the third command prints 0. That zero is the lesson: anything placed in an excluded path is invisible to the scanner, so exclusions stay as narrow as the vendor's list, documented, and reviewed.

Notes

EDR products add behaviour-based detection that can still notice activity in an excluded folder, such as a process encrypting many files quickly. Signature scanning alone cannot.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.