CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 951–1,000 of 5,000 matching questions

50 per page
0951
Module 2 · Foundation Domain 2 · Analysis / Assessment passive reconnaissance Unanswered

During an authorized retail-company assessment (RET-LAB-M02-951), which evidence best supports an assessment of "passive reconnaissance"?

View answer choices
  1. Registrar records showing nameservers, dates, status codes, and registration contacts.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Authoritative DNS responses and a validated map of relevant record types.
  4. OSINT findings documented with source, date, relevance, and confidence.
Practice
0952
Module 2 · Foundation Domain 2 · Analysis / Assessment passive reconnaissance Unanswered

During a hospital incident-response exercise (HLT-SOC-M02-952), which evidence best supports an assessment of "passive reconnaissance"?

View answer choices
  1. Registrar records showing nameservers, dates, status codes, and registration contacts.
  2. Timestamped probe logs matched to the approved source and scope.
  3. OSINT findings documented with source, date, relevance, and confidence.
  4. Authoritative DNS responses and a validated map of relevant record types.
Practice
0953
Module 2 · Foundation Domain 2 · Analysis / Assessment passive reconnaissance Unanswered

During a university cyber-range engagement (EDU-RANGE-M02-953), which evidence best supports an assessment of "passive reconnaissance"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Timestamped probe logs matched to the approved source and scope.
  3. OSINT findings documented with source, date, relevance, and confidence.
  4. Registrar records showing nameservers, dates, status codes, and registration contacts.
Practice
0954
Module 2 · Applied Domain 2 · Analysis / Assessment passive reconnaissance Unanswered

During a financial-services purple-team test (FIN-PT-M02-954), which evidence best supports an assessment of "passive reconnaissance"?

View answer choices
  1. OSINT findings documented with source, date, relevance, and confidence.
  2. Registrar records showing nameservers, dates, status codes, and registration contacts.
  3. Authoritative DNS responses and a validated map of relevant record types.
  4. Timestamped probe logs matched to the approved source and scope.
Practice
0955
Module 2 · Applied Domain 2 · Analysis / Assessment passive reconnaissance Unanswered

During a cloud startup security audit (CLD-AUDIT-M02-955), which evidence best supports an assessment of "passive reconnaissance"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Registrar records showing nameservers, dates, status codes, and registration contacts.
  3. Timestamped probe logs matched to the approved source and scope.
  4. OSINT findings documented with source, date, relevance, and confidence.
Practice
0956
Module 2 · Applied Domain 2 · Analysis / Assessment passive reconnaissance Unanswered

During a government risk-validation project (GOV-RISK-M02-956), which evidence best supports an assessment of "passive reconnaissance"?

View answer choices
  1. Registrar records showing nameservers, dates, status codes, and registration contacts.
  2. Timestamped probe logs matched to the approved source and scope.
  3. OSINT findings documented with source, date, relevance, and confidence.
  4. Authoritative DNS responses and a validated map of relevant record types.
Practice
0957
Module 2 · Applied Domain 2 · Analysis / Assessment passive reconnaissance Unanswered

During an e-commerce application review (ECOM-WEB-M02-957), which evidence best supports an assessment of "passive reconnaissance"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. OSINT findings documented with source, date, relevance, and confidence.
  3. Timestamped probe logs matched to the approved source and scope.
  4. Registrar records showing nameservers, dates, status codes, and registration contacts.
Practice
0958
Module 2 · Advanced Domain 2 · Analysis / Assessment passive reconnaissance Unanswered

During a manufacturing and OT security review (MFG-OT-M02-958), which evidence best supports an assessment of "passive reconnaissance"?

View answer choices
  1. Registrar records showing nameservers, dates, status codes, and registration contacts.
  2. Authoritative DNS responses and a validated map of relevant record types.
  3. OSINT findings documented with source, date, relevance, and confidence.
  4. Timestamped probe logs matched to the approved source and scope.
Practice
0959
Module 2 · Advanced Domain 2 · Analysis / Assessment passive reconnaissance Unanswered

During a mobile-services penetration test (MOB-TEST-M02-959), which evidence best supports an assessment of "passive reconnaissance"?

View answer choices
  1. Registrar records showing nameservers, dates, status codes, and registration contacts.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Authoritative DNS responses and a validated map of relevant record types.
  4. OSINT findings documented with source, date, relevance, and confidence.
Practice
0960
Module 2 · Advanced Domain 2 · Analysis / Assessment passive reconnaissance Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M02-960), which evidence best supports an assessment of "passive reconnaissance"?

View answer choices
  1. OSINT findings documented with source, date, relevance, and confidence.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Registrar records showing nameservers, dates, status codes, and registration contacts.
  4. Authoritative DNS responses and a validated map of relevant record types.
Practice
0961
Module 2 · Foundation Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During an authorized retail-company assessment (RET-LAB-M02-961), which statement most accurately defines "search-engine reconnaissance"?

View answer choices
  1. Information gathering that directly interacts with target infrastructure or personnel.
  2. Use of indexed public information and advanced search operators to find target exposure.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
0962
Module 2 · Foundation Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a hospital incident-response exercise (HLT-SOC-M02-962), which statement most accurately defines "search-engine reconnaissance"?

View answer choices
  1. Use of indexed public information and advanced search operators to find target exposure.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
0963
Module 2 · Foundation Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a university cyber-range engagement (EDU-RANGE-M02-963), which statement most accurately defines "search-engine reconnaissance"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Use of indexed public information and advanced search operators to find target exposure.
Practice
0964
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a financial-services purple-team test (FIN-PT-M02-964), which statement most accurately defines "search-engine reconnaissance"?

View answer choices
  1. Use of indexed public information and advanced search operators to find target exposure.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
0965
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a cloud startup security audit (CLD-AUDIT-M02-965), which statement most accurately defines "search-engine reconnaissance"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Use of indexed public information and advanced search operators to find target exposure.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
0966
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a government risk-validation project (GOV-RISK-M02-966), which statement most accurately defines "search-engine reconnaissance"?

View answer choices
  1. Use of indexed public information and advanced search operators to find target exposure.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
0967
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During an e-commerce application review (ECOM-WEB-M02-967), which statement most accurately defines "search-engine reconnaissance"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Use of indexed public information and advanced search operators to find target exposure.
Practice
0968
Module 2 · Advanced Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a manufacturing and OT security review (MFG-OT-M02-968), which statement most accurately defines "search-engine reconnaissance"?

View answer choices
  1. Use of indexed public information and advanced search operators to find target exposure.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
0969
Module 2 · Advanced Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a mobile-services penetration test (MOB-TEST-M02-969), which statement most accurately defines "search-engine reconnaissance"?

View answer choices
  1. Information gathering that directly interacts with target infrastructure or personnel.
  2. Use of indexed public information and advanced search operators to find target exposure.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
0970
Module 2 · Advanced Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M02-970), which statement most accurately defines "search-engine reconnaissance"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Use of indexed public information and advanced search operators to find target exposure.
Practice
0971
Module 2 · Foundation Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During an authorized retail-company assessment (RET-LAB-M02-971), which risk is most directly associated with "search-engine reconnaissance"?

View answer choices
  1. Indexed documents, backups, and error pages may disclose credentials or internal details.
  2. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
0972
Module 2 · Foundation Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a hospital incident-response exercise (HLT-SOC-M02-972), which risk is most directly associated with "search-engine reconnaissance"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Indexed documents, backups, and error pages may disclose credentials or internal details.
  3. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
0973
Module 2 · Foundation Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a university cyber-range engagement (EDU-RANGE-M02-973), which risk is most directly associated with "search-engine reconnaissance"?

View answer choices
  1. Indexed documents, backups, and error pages may disclose credentials or internal details.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
Practice
0974
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a financial-services purple-team test (FIN-PT-M02-974), which risk is most directly associated with "search-engine reconnaissance"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  3. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  4. Indexed documents, backups, and error pages may disclose credentials or internal details.
Practice
0975
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a cloud startup security audit (CLD-AUDIT-M02-975), which risk is most directly associated with "search-engine reconnaissance"?

View answer choices
  1. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  2. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  3. Indexed documents, backups, and error pages may disclose credentials or internal details.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
0976
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a government risk-validation project (GOV-RISK-M02-976), which risk is most directly associated with "search-engine reconnaissance"?

View answer choices
  1. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  2. Indexed documents, backups, and error pages may disclose credentials or internal details.
  3. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
0977
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During an e-commerce application review (ECOM-WEB-M02-977), which risk is most directly associated with "search-engine reconnaissance"?

View answer choices
  1. Indexed documents, backups, and error pages may disclose credentials or internal details.
  2. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  3. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  4. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
Practice
0978
Module 2 · Advanced Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a manufacturing and OT security review (MFG-OT-M02-978), which risk is most directly associated with "search-engine reconnaissance"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Indexed documents, backups, and error pages may disclose credentials or internal details.
Practice
0979
Module 2 · Advanced Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a mobile-services penetration test (MOB-TEST-M02-979), which risk is most directly associated with "search-engine reconnaissance"?

View answer choices
  1. Indexed documents, backups, and error pages may disclose credentials or internal details.
  2. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  3. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
0980
Module 2 · Advanced Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M02-980), which risk is most directly associated with "search-engine reconnaissance"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Indexed documents, backups, and error pages may disclose credentials or internal details.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
0981
Module 2 · Foundation Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During an authorized retail-company assessment (RET-LAB-M02-981), which action most directly controls the risk related to "search-engine reconnaissance"?

View answer choices
  1. Remove sensitive content, configure access correctly, and request de-indexing where appropriate.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
0982
Module 2 · Foundation Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a hospital incident-response exercise (HLT-SOC-M02-982), which action most directly controls the risk related to "search-engine reconnaissance"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Remove sensitive content, configure access correctly, and request de-indexing where appropriate.
Practice
0983
Module 2 · Foundation Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a university cyber-range engagement (EDU-RANGE-M02-983), which action most directly controls the risk related to "search-engine reconnaissance"?

View answer choices
  1. Remove sensitive content, configure access correctly, and request de-indexing where appropriate.
  2. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Define permitted techniques and rates in the rules of engagement.
Practice
0984
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a financial-services purple-team test (FIN-PT-M02-984), which action most directly controls the risk related to "search-engine reconnaissance"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Remove sensitive content, configure access correctly, and request de-indexing where appropriate.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Use appropriate registration privacy and monitor unauthorized domain changes.
Practice
0985
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a cloud startup security audit (CLD-AUDIT-M02-985), which action most directly controls the risk related to "search-engine reconnaissance"?

View answer choices
  1. Remove sensitive content, configure access correctly, and request de-indexing where appropriate.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
0986
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a government risk-validation project (GOV-RISK-M02-986), which action most directly controls the risk related to "search-engine reconnaissance"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Remove sensitive content, configure access correctly, and request de-indexing where appropriate.
Practice
0987
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During an e-commerce application review (ECOM-WEB-M02-987), which action most directly controls the risk related to "search-engine reconnaissance"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  3. Remove sensitive content, configure access correctly, and request de-indexing where appropriate.
  4. Define permitted techniques and rates in the rules of engagement.
Practice
0988
Module 2 · Advanced Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a manufacturing and OT security review (MFG-OT-M02-988), which action most directly controls the risk related to "search-engine reconnaissance"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Remove sensitive content, configure access correctly, and request de-indexing where appropriate.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Use appropriate registration privacy and monitor unauthorized domain changes.
Practice
0989
Module 2 · Advanced Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a mobile-services penetration test (MOB-TEST-M02-989), which action most directly controls the risk related to "search-engine reconnaissance"?

View answer choices
  1. Remove sensitive content, configure access correctly, and request de-indexing where appropriate.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
0990
Module 2 · Advanced Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M02-990), which action most directly controls the risk related to "search-engine reconnaissance"?

View answer choices
  1. Remove sensitive content, configure access correctly, and request de-indexing where appropriate.
  2. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Define permitted techniques and rates in the rules of engagement.
Practice
0991
Module 2 · Foundation Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During an authorized retail-company assessment (RET-LAB-M02-991), which evidence best supports an assessment of "search-engine reconnaissance"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Registrar records showing nameservers, dates, status codes, and registration contacts.
  4. Search results preserving the query, URL, cache state, and exposed data classification.
Practice
0992
Module 2 · Foundation Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a hospital incident-response exercise (HLT-SOC-M02-992), which evidence best supports an assessment of "search-engine reconnaissance"?

View answer choices
  1. Search results preserving the query, URL, cache state, and exposed data classification.
  2. Registrar records showing nameservers, dates, status codes, and registration contacts.
  3. Timestamped probe logs matched to the approved source and scope.
  4. Authoritative DNS responses and a validated map of relevant record types.
Practice
0993
Module 2 · Foundation Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a university cyber-range engagement (EDU-RANGE-M02-993), which evidence best supports an assessment of "search-engine reconnaissance"?

View answer choices
  1. Timestamped probe logs matched to the approved source and scope.
  2. Search results preserving the query, URL, cache state, and exposed data classification.
  3. Authoritative DNS responses and a validated map of relevant record types.
  4. Registrar records showing nameservers, dates, status codes, and registration contacts.
Practice
0994
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a financial-services purple-team test (FIN-PT-M02-994), which evidence best supports an assessment of "search-engine reconnaissance"?

View answer choices
  1. Search results preserving the query, URL, cache state, and exposed data classification.
  2. Authoritative DNS responses and a validated map of relevant record types.
  3. Registrar records showing nameservers, dates, status codes, and registration contacts.
  4. Timestamped probe logs matched to the approved source and scope.
Practice
0995
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a cloud startup security audit (CLD-AUDIT-M02-995), which evidence best supports an assessment of "search-engine reconnaissance"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Registrar records showing nameservers, dates, status codes, and registration contacts.
  3. Timestamped probe logs matched to the approved source and scope.
  4. Search results preserving the query, URL, cache state, and exposed data classification.
Practice
0996
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a government risk-validation project (GOV-RISK-M02-996), which evidence best supports an assessment of "search-engine reconnaissance"?

View answer choices
  1. Registrar records showing nameservers, dates, status codes, and registration contacts.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Search results preserving the query, URL, cache state, and exposed data classification.
  4. Authoritative DNS responses and a validated map of relevant record types.
Practice
0997
Module 2 · Applied Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During an e-commerce application review (ECOM-WEB-M02-997), which evidence best supports an assessment of "search-engine reconnaissance"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Search results preserving the query, URL, cache state, and exposed data classification.
  4. Registrar records showing nameservers, dates, status codes, and registration contacts.
Practice
0998
Module 2 · Advanced Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a manufacturing and OT security review (MFG-OT-M02-998), which evidence best supports an assessment of "search-engine reconnaissance"?

View answer choices
  1. Registrar records showing nameservers, dates, status codes, and registration contacts.
  2. Authoritative DNS responses and a validated map of relevant record types.
  3. Search results preserving the query, URL, cache state, and exposed data classification.
  4. Timestamped probe logs matched to the approved source and scope.
Practice
0999
Module 2 · Advanced Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a mobile-services penetration test (MOB-TEST-M02-999), which evidence best supports an assessment of "search-engine reconnaissance"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Registrar records showing nameservers, dates, status codes, and registration contacts.
  3. Timestamped probe logs matched to the approved source and scope.
  4. Search results preserving the query, URL, cache state, and exposed data classification.
Practice
1000
Module 2 · Advanced Domain 2 · Analysis / Assessment search-engine reconnaissance Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M02-1000), which evidence best supports an assessment of "search-engine reconnaissance"?

View answer choices
  1. Search results preserving the query, URL, cache state, and exposed data classification.
  2. Registrar records showing nameservers, dates, status codes, and registration contacts.
  3. Timestamped probe logs matched to the approved source and scope.
  4. Authoritative DNS responses and a validated map of relevant record types.
Practice