CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 601–650 of 5,000 matching questions

50 per page
0601
Module 1 · Foundation Domain 6 · Regulation / Policy PCI DSS Unanswered

During an authorized retail-company assessment (RET-LAB-M01-601), which statement most accurately defines "PCI DSS"?

View answer choices
  1. A payment-card security standard defining technical and operational requirements for protecting account data.
  2. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
0602
Module 1 · Foundation Domain 6 · Regulation / Policy PCI DSS Unanswered

During a hospital incident-response exercise (HLT-SOC-M01-602), which statement most accurately defines "PCI DSS"?

View answer choices
  1. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
  2. A payment-card security standard defining technical and operational requirements for protecting account data.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
0603
Module 1 · Foundation Domain 6 · Regulation / Policy PCI DSS Unanswered

During a university cyber-range engagement (EDU-RANGE-M01-603), which statement most accurately defines "PCI DSS"?

View answer choices
  1. A payment-card security standard defining technical and operational requirements for protecting account data.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
Practice
0604
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During a financial-services purple-team test (FIN-PT-M01-604), which statement most accurately defines "PCI DSS"?

View answer choices
  1. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. A payment-card security standard defining technical and operational requirements for protecting account data.
Practice
0605
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During a cloud startup security audit (CLD-AUDIT-M01-605), which statement most accurately defines "PCI DSS"?

View answer choices
  1. A payment-card security standard defining technical and operational requirements for protecting account data.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
0606
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During a government risk-validation project (GOV-RISK-M01-606), which statement most accurately defines "PCI DSS"?

View answer choices
  1. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
  2. A payment-card security standard defining technical and operational requirements for protecting account data.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
0607
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During an e-commerce application review (ECOM-WEB-M01-607), which statement most accurately defines "PCI DSS"?

View answer choices
  1. A payment-card security standard defining technical and operational requirements for protecting account data.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
Practice
0608
Module 1 · Advanced Domain 6 · Regulation / Policy PCI DSS Unanswered

During a manufacturing and OT security review (MFG-OT-M01-608), which statement most accurately defines "PCI DSS"?

View answer choices
  1. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A payment-card security standard defining technical and operational requirements for protecting account data.
Practice
0609
Module 1 · Advanced Domain 6 · Regulation / Policy PCI DSS Unanswered

During a mobile-services penetration test (MOB-TEST-M01-609), which statement most accurately defines "PCI DSS"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
  3. A payment-card security standard defining technical and operational requirements for protecting account data.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
0610
Module 1 · Advanced Domain 6 · Regulation / Policy PCI DSS Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M01-610), which statement most accurately defines "PCI DSS"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. A payment-card security standard defining technical and operational requirements for protecting account data.
  4. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
Practice
0611
Module 1 · Foundation Domain 6 · Regulation / Policy PCI DSS Unanswered

During an authorized retail-company assessment (RET-LAB-M01-611), which risk is most directly associated with "PCI DSS"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Failure to protect cardholder data can lead to fraud, contractual penalties, and loss of processing trust.
  3. Unauthorized collection or exposure can harm individuals and create regulatory liability.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
0612
Module 1 · Foundation Domain 6 · Regulation / Policy PCI DSS Unanswered

During a hospital incident-response exercise (HLT-SOC-M01-612), which risk is most directly associated with "PCI DSS"?

View answer choices
  1. Failure to protect cardholder data can lead to fraud, contractual penalties, and loss of processing trust.
  2. Unauthorized collection or exposure can harm individuals and create regulatory liability.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
0613
Module 1 · Foundation Domain 6 · Regulation / Policy PCI DSS Unanswered

During a university cyber-range engagement (EDU-RANGE-M01-613), which risk is most directly associated with "PCI DSS"?

View answer choices
  1. Unauthorized collection or exposure can harm individuals and create regulatory liability.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Failure to protect cardholder data can lead to fraud, contractual penalties, and loss of processing trust.
Practice
0614
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During a financial-services purple-team test (FIN-PT-M01-614), which risk is most directly associated with "PCI DSS"?

View answer choices
  1. Failure to protect cardholder data can lead to fraud, contractual penalties, and loss of processing trust.
  2. A control focused on only one objective can leave the other security objectives exposed.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Unauthorized collection or exposure can harm individuals and create regulatory liability.
Practice
0615
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During a cloud startup security audit (CLD-AUDIT-M01-615), which risk is most directly associated with "PCI DSS"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Failure to protect cardholder data can lead to fraud, contractual penalties, and loss of processing trust.
  3. Unauthorized collection or exposure can harm individuals and create regulatory liability.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
0616
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During a government risk-validation project (GOV-RISK-M01-616), which risk is most directly associated with "PCI DSS"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unauthorized collection or exposure can harm individuals and create regulatory liability.
  3. Failure to protect cardholder data can lead to fraud, contractual penalties, and loss of processing trust.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
0617
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During an e-commerce application review (ECOM-WEB-M01-617), which risk is most directly associated with "PCI DSS"?

View answer choices
  1. Unauthorized collection or exposure can harm individuals and create regulatory liability.
  2. A control focused on only one objective can leave the other security objectives exposed.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Failure to protect cardholder data can lead to fraud, contractual penalties, and loss of processing trust.
Practice
0618
Module 1 · Advanced Domain 6 · Regulation / Policy PCI DSS Unanswered

During a manufacturing and OT security review (MFG-OT-M01-618), which risk is most directly associated with "PCI DSS"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Failure to protect cardholder data can lead to fraud, contractual penalties, and loss of processing trust.
  4. Unauthorized collection or exposure can harm individuals and create regulatory liability.
Practice
0619
Module 1 · Advanced Domain 6 · Regulation / Policy PCI DSS Unanswered

During a mobile-services penetration test (MOB-TEST-M01-619), which risk is most directly associated with "PCI DSS"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Failure to protect cardholder data can lead to fraud, contractual penalties, and loss of processing trust.
  3. Unauthorized collection or exposure can harm individuals and create regulatory liability.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
0620
Module 1 · Advanced Domain 6 · Regulation / Policy PCI DSS Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M01-620), which risk is most directly associated with "PCI DSS"?

View answer choices
  1. Failure to protect cardholder data can lead to fraud, contractual penalties, and loss of processing trust.
  2. Unauthorized collection or exposure can harm individuals and create regulatory liability.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
0621
Module 1 · Foundation Domain 6 · Regulation / Policy PCI DSS Unanswered

During an authorized retail-company assessment (RET-LAB-M01-621), which action most directly controls the risk related to "PCI DSS"?

View answer choices
  1. Apply purpose limitation, minimization, access control, retention, and breach procedures.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Define the cardholder-data environment, minimize data, and validate required controls.
Practice
0622
Module 1 · Foundation Domain 6 · Regulation / Policy PCI DSS Unanswered

During a hospital incident-response exercise (HLT-SOC-M01-622), which action most directly controls the risk related to "PCI DSS"?

View answer choices
  1. Define the cardholder-data environment, minimize data, and validate required controls.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Apply purpose limitation, minimization, access control, retention, and breach procedures.
Practice
0623
Module 1 · Foundation Domain 6 · Regulation / Policy PCI DSS Unanswered

During a university cyber-range engagement (EDU-RANGE-M01-623), which action most directly controls the risk related to "PCI DSS"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Define the cardholder-data environment, minimize data, and validate required controls.
  3. Apply purpose limitation, minimization, access control, retention, and breach procedures.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
0624
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During a financial-services purple-team test (FIN-PT-M01-624), which action most directly controls the risk related to "PCI DSS"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Apply purpose limitation, minimization, access control, retention, and breach procedures.
  3. Define the cardholder-data environment, minimize data, and validate required controls.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
0625
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During a cloud startup security audit (CLD-AUDIT-M01-625), which action most directly controls the risk related to "PCI DSS"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Apply purpose limitation, minimization, access control, retention, and breach procedures.
  4. Define the cardholder-data environment, minimize data, and validate required controls.
Practice
0626
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During a government risk-validation project (GOV-RISK-M01-626), which action most directly controls the risk related to "PCI DSS"?

View answer choices
  1. Define the cardholder-data environment, minimize data, and validate required controls.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Apply purpose limitation, minimization, access control, retention, and breach procedures.
Practice
0627
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During an e-commerce application review (ECOM-WEB-M01-627), which action most directly controls the risk related to "PCI DSS"?

View answer choices
  1. Apply purpose limitation, minimization, access control, retention, and breach procedures.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Define the cardholder-data environment, minimize data, and validate required controls.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
0628
Module 1 · Advanced Domain 6 · Regulation / Policy PCI DSS Unanswered

During a manufacturing and OT security review (MFG-OT-M01-628), which action most directly controls the risk related to "PCI DSS"?

View answer choices
  1. Define the cardholder-data environment, minimize data, and validate required controls.
  2. Apply purpose limitation, minimization, access control, retention, and breach procedures.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
0629
Module 1 · Advanced Domain 6 · Regulation / Policy PCI DSS Unanswered

During a mobile-services penetration test (MOB-TEST-M01-629), which action most directly controls the risk related to "PCI DSS"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Apply purpose limitation, minimization, access control, retention, and breach procedures.
  4. Define the cardholder-data environment, minimize data, and validate required controls.
Practice
0630
Module 1 · Advanced Domain 6 · Regulation / Policy PCI DSS Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M01-630), which action most directly controls the risk related to "PCI DSS"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Define the cardholder-data environment, minimize data, and validate required controls.
  3. Apply purpose limitation, minimization, access control, retention, and breach procedures.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
0631
Module 1 · Foundation Domain 6 · Regulation / Policy PCI DSS Unanswered

During an authorized retail-company assessment (RET-LAB-M01-631), which evidence best supports an assessment of "PCI DSS"?

View answer choices
  1. An approved scope and assessment evidence for systems storing, processing, or transmitting account data.
  2. A risk register linking assets to CIA impact ratings.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A data inventory linking purpose, legal basis, location, retention, controls, and owner.
Practice
0632
Module 1 · Foundation Domain 6 · Regulation / Policy PCI DSS Unanswered

During a hospital incident-response exercise (HLT-SOC-M01-632), which evidence best supports an assessment of "PCI DSS"?

View answer choices
  1. A data inventory linking purpose, legal basis, location, retention, controls, and owner.
  2. A risk register linking assets to CIA impact ratings.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. An approved scope and assessment evidence for systems storing, processing, or transmitting account data.
Practice
0633
Module 1 · Foundation Domain 6 · Regulation / Policy PCI DSS Unanswered

During a university cyber-range engagement (EDU-RANGE-M01-633), which evidence best supports an assessment of "PCI DSS"?

View answer choices
  1. An approved scope and assessment evidence for systems storing, processing, or transmitting account data.
  2. A risk register linking assets to CIA impact ratings.
  3. A data inventory linking purpose, legal basis, location, retention, controls, and owner.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
0634
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During a financial-services purple-team test (FIN-PT-M01-634), which evidence best supports an assessment of "PCI DSS"?

View answer choices
  1. A data inventory linking purpose, legal basis, location, retention, controls, and owner.
  2. An approved scope and assessment evidence for systems storing, processing, or transmitting account data.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A risk register linking assets to CIA impact ratings.
Practice
0635
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During a cloud startup security audit (CLD-AUDIT-M01-635), which evidence best supports an assessment of "PCI DSS"?

View answer choices
  1. An approved scope and assessment evidence for systems storing, processing, or transmitting account data.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A risk register linking assets to CIA impact ratings.
  4. A data inventory linking purpose, legal basis, location, retention, controls, and owner.
Practice
0636
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During a government risk-validation project (GOV-RISK-M01-636), which evidence best supports an assessment of "PCI DSS"?

View answer choices
  1. A data inventory linking purpose, legal basis, location, retention, controls, and owner.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A risk register linking assets to CIA impact ratings.
  4. An approved scope and assessment evidence for systems storing, processing, or transmitting account data.
Practice
0637
Module 1 · Applied Domain 6 · Regulation / Policy PCI DSS Unanswered

During an e-commerce application review (ECOM-WEB-M01-637), which evidence best supports an assessment of "PCI DSS"?

View answer choices
  1. An approved scope and assessment evidence for systems storing, processing, or transmitting account data.
  2. A risk register linking assets to CIA impact ratings.
  3. A data inventory linking purpose, legal basis, location, retention, controls, and owner.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
0638
Module 1 · Advanced Domain 6 · Regulation / Policy PCI DSS Unanswered

During a manufacturing and OT security review (MFG-OT-M01-638), which evidence best supports an assessment of "PCI DSS"?

View answer choices
  1. A data inventory linking purpose, legal basis, location, retention, controls, and owner.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. An approved scope and assessment evidence for systems storing, processing, or transmitting account data.
  4. A risk register linking assets to CIA impact ratings.
Practice
0639
Module 1 · Advanced Domain 6 · Regulation / Policy PCI DSS Unanswered

During a mobile-services penetration test (MOB-TEST-M01-639), which evidence best supports an assessment of "PCI DSS"?

View answer choices
  1. An approved scope and assessment evidence for systems storing, processing, or transmitting account data.
  2. A risk register linking assets to CIA impact ratings.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A data inventory linking purpose, legal basis, location, retention, controls, and owner.
Practice
0640
Module 1 · Advanced Domain 6 · Regulation / Policy PCI DSS Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M01-640), which evidence best supports an assessment of "PCI DSS"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A data inventory linking purpose, legal basis, location, retention, controls, and owner.
  3. An approved scope and assessment evidence for systems storing, processing, or transmitting account data.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
0641
Module 1 · Foundation Domain 6 · Regulation / Policy data-protection policy and law Unanswered

During an authorized retail-company assessment (RET-LAB-M01-641), which statement most accurately defines "data-protection policy and law"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. A payment-card security standard defining technical and operational requirements for protecting account data.
  4. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
Practice
0642
Module 1 · Foundation Domain 6 · Regulation / Policy data-protection policy and law Unanswered

During a hospital incident-response exercise (HLT-SOC-M01-642), which statement most accurately defines "data-protection policy and law"?

View answer choices
  1. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. A payment-card security standard defining technical and operational requirements for protecting account data.
Practice
0643
Module 1 · Foundation Domain 6 · Regulation / Policy data-protection policy and law Unanswered

During a university cyber-range engagement (EDU-RANGE-M01-643), which statement most accurately defines "data-protection policy and law"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
  3. A payment-card security standard defining technical and operational requirements for protecting account data.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
0644
Module 1 · Applied Domain 6 · Regulation / Policy data-protection policy and law Unanswered

During a financial-services purple-team test (FIN-PT-M01-644), which statement most accurately defines "data-protection policy and law"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A payment-card security standard defining technical and operational requirements for protecting account data.
  3. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
0645
Module 1 · Applied Domain 6 · Regulation / Policy data-protection policy and law Unanswered

During a cloud startup security audit (CLD-AUDIT-M01-645), which statement most accurately defines "data-protection policy and law"?

View answer choices
  1. A payment-card security standard defining technical and operational requirements for protecting account data.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
Practice
0646
Module 1 · Applied Domain 6 · Regulation / Policy data-protection policy and law Unanswered

During a government risk-validation project (GOV-RISK-M01-646), which statement most accurately defines "data-protection policy and law"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
  4. A payment-card security standard defining technical and operational requirements for protecting account data.
Practice
0647
Module 1 · Applied Domain 6 · Regulation / Policy data-protection policy and law Unanswered

During an e-commerce application review (ECOM-WEB-M01-647), which statement most accurately defines "data-protection policy and law"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
  3. A payment-card security standard defining technical and operational requirements for protecting account data.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
0648
Module 1 · Advanced Domain 6 · Regulation / Policy data-protection policy and law Unanswered

During a manufacturing and OT security review (MFG-OT-M01-648), which statement most accurately defines "data-protection policy and law"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A payment-card security standard defining technical and operational requirements for protecting account data.
  3. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
0649
Module 1 · Advanced Domain 6 · Regulation / Policy data-protection policy and law Unanswered

During a mobile-services penetration test (MOB-TEST-M01-649), which statement most accurately defines "data-protection policy and law"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. A payment-card security standard defining technical and operational requirements for protecting account data.
  4. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
Practice
0650
Module 1 · Advanced Domain 6 · Regulation / Policy data-protection policy and law Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M01-650), which statement most accurately defines "data-protection policy and law"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. Requirements governing lawful handling, protection, retention, and disclosure of personal data.
  3. A payment-card security standard defining technical and operational requirements for protecting account data.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice