CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 1,051–1,100 of 5,000 matching questions

50 per page
1051
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During an authorized retail-company assessment (RET-LAB-M02-1051), which risk is most directly associated with "Recon-ng"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Registration metadata can support infrastructure mapping and impersonation.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Automated modules can query third parties or collect data outside scope.
Practice
1052
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a hospital incident-response exercise (HLT-SOC-M02-1052), which risk is most directly associated with "Recon-ng"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Registration metadata can support infrastructure mapping and impersonation.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
1053
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a university cyber-range engagement (EDU-RANGE-M02-1053), which risk is most directly associated with "Recon-ng"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Automated modules can query third parties or collect data outside scope.
  3. Registration metadata can support infrastructure mapping and impersonation.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
1054
Module 2 · Applied Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a financial-services purple-team test (FIN-PT-M02-1054), which risk is most directly associated with "Recon-ng"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Registration metadata can support infrastructure mapping and impersonation.
Practice
1055
Module 2 · Applied Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a cloud startup security audit (CLD-AUDIT-M02-1055), which risk is most directly associated with "Recon-ng"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Registration metadata can support infrastructure mapping and impersonation.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Automated modules can query third parties or collect data outside scope.
Practice
1056
Module 2 · Applied Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a government risk-validation project (GOV-RISK-M02-1056), which risk is most directly associated with "Recon-ng"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Registration metadata can support infrastructure mapping and impersonation.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
1057
Module 2 · Applied Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During an e-commerce application review (ECOM-WEB-M02-1057), which risk is most directly associated with "Recon-ng"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Automated modules can query third parties or collect data outside scope.
  3. Registration metadata can support infrastructure mapping and impersonation.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
1058
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a manufacturing and OT security review (MFG-OT-M02-1058), which risk is most directly associated with "Recon-ng"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Registration metadata can support infrastructure mapping and impersonation.
Practice
1059
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a mobile-services penetration test (MOB-TEST-M02-1059), which risk is most directly associated with "Recon-ng"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Registration metadata can support infrastructure mapping and impersonation.
  4. Automated modules can query third parties or collect data outside scope.
Practice
1060
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M02-1060), which risk is most directly associated with "Recon-ng"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Registration metadata can support infrastructure mapping and impersonation.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
1061
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During an authorized retail-company assessment (RET-LAB-M02-1061), which action most directly controls the risk related to "Recon-ng"?

View answer choices
  1. Use privacy appropriately and monitor domains for unauthorized changes.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
1062
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a hospital incident-response exercise (HLT-SOC-M02-1062), which action most directly controls the risk related to "Recon-ng"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Use privacy appropriately and monitor domains for unauthorized changes.
Practice
1063
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a university cyber-range engagement (EDU-RANGE-M02-1063), which action most directly controls the risk related to "Recon-ng"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Use privacy appropriately and monitor domains for unauthorized changes.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
1064
Module 2 · Applied Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a financial-services purple-team test (FIN-PT-M02-1064), which action most directly controls the risk related to "Recon-ng"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Use privacy appropriately and monitor domains for unauthorized changes.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
1065
Module 2 · Applied Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a cloud startup security audit (CLD-AUDIT-M02-1065), which action most directly controls the risk related to "Recon-ng"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Use privacy appropriately and monitor domains for unauthorized changes.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
1066
Module 2 · Applied Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a government risk-validation project (GOV-RISK-M02-1066), which action most directly controls the risk related to "Recon-ng"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Use privacy appropriately and monitor domains for unauthorized changes.
Practice
1067
Module 2 · Applied Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During an e-commerce application review (ECOM-WEB-M02-1067), which action most directly controls the risk related to "Recon-ng"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Use privacy appropriately and monitor domains for unauthorized changes.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
1068
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a manufacturing and OT security review (MFG-OT-M02-1068), which action most directly controls the risk related to "Recon-ng"?

View answer choices
  1. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  2. Use privacy appropriately and monitor domains for unauthorized changes.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
1069
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a mobile-services penetration test (MOB-TEST-M02-1069), which action most directly controls the risk related to "Recon-ng"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Use privacy appropriately and monitor domains for unauthorized changes.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
1070
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M02-1070), which action most directly controls the risk related to "Recon-ng"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Use privacy appropriately and monitor domains for unauthorized changes.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
1071
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During an authorized retail-company assessment (RET-LAB-M02-1071), which evidence best supports an assessment of "Recon-ng"?

View answer choices
  1. Search results validated against the organization’s current external inventory.
  2. A relationship graph retaining sources and transformation history.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Timestamped registry output from the authoritative registration service.
Practice
1072
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a hospital incident-response exercise (HLT-SOC-M02-1072), which evidence best supports an assessment of "Recon-ng"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. Timestamped registry output from the authoritative registration service.
  4. Search results validated against the organization’s current external inventory.
Practice
1073
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a university cyber-range engagement (EDU-RANGE-M02-1073), which evidence best supports an assessment of "Recon-ng"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. Timestamped registry output from the authoritative registration service.
  3. Search results validated against the organization’s current external inventory.
  4. A relationship graph retaining sources and transformation history.
Practice
1074
Module 2 · Applied Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a financial-services purple-team test (FIN-PT-M02-1074), which evidence best supports an assessment of "Recon-ng"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Timestamped registry output from the authoritative registration service.
  3. Search results validated against the organization’s current external inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
1075
Module 2 · Applied Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a cloud startup security audit (CLD-AUDIT-M02-1075), which evidence best supports an assessment of "Recon-ng"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. A relationship graph retaining sources and transformation history.
  3. Search results validated against the organization’s current external inventory.
  4. Timestamped registry output from the authoritative registration service.
Practice
1076
Module 2 · Applied Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a government risk-validation project (GOV-RISK-M02-1076), which evidence best supports an assessment of "Recon-ng"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Timestamped registry output from the authoritative registration service.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Search results validated against the organization’s current external inventory.
Practice
1077
Module 2 · Applied Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During an e-commerce application review (ECOM-WEB-M02-1077), which evidence best supports an assessment of "Recon-ng"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. Timestamped registry output from the authoritative registration service.
  3. Search results validated against the organization’s current external inventory.
  4. A relationship graph retaining sources and transformation history.
Practice
1078
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a manufacturing and OT security review (MFG-OT-M02-1078), which evidence best supports an assessment of "Recon-ng"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Timestamped registry output from the authoritative registration service.
  3. Search results validated against the organization’s current external inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
1079
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a mobile-services penetration test (MOB-TEST-M02-1079), which evidence best supports an assessment of "Recon-ng"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. A relationship graph retaining sources and transformation history.
  3. Search results validated against the organization’s current external inventory.
  4. Timestamped registry output from the authoritative registration service.
Practice
1080
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Recon-ng Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M02-1080), which evidence best supports an assessment of "Recon-ng"?

View answer choices
  1. Timestamped registry output from the authoritative registration service.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. A relationship graph retaining sources and transformation history.
  4. Search results validated against the organization’s current external inventory.
Practice
1081
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Shodan Unanswered

During an authorized retail-company assessment (RET-LAB-M02-1081), which statement most accurately defines "Shodan"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A utility for retrieving domain or IP registration and allocation information.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
1082
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a hospital incident-response exercise (HLT-SOC-M02-1082), which statement most accurately defines "Shodan"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A utility for retrieving domain or IP registration and allocation information.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
1083
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a university cyber-range engagement (EDU-RANGE-M02-1083), which statement most accurately defines "Shodan"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A utility for retrieving domain or IP registration and allocation information.
Practice
1084
Module 2 · Applied Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a financial-services purple-team test (FIN-PT-M02-1084), which statement most accurately defines "Shodan"?

View answer choices
  1. A utility for retrieving domain or IP registration and allocation information.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
1085
Module 2 · Applied Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a cloud startup security audit (CLD-AUDIT-M02-1085), which statement most accurately defines "Shodan"?

View answer choices
  1. A search service that indexes Internet-connected devices and service banners.
  2. A utility for retrieving domain or IP registration and allocation information.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
1086
Module 2 · Applied Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a government risk-validation project (GOV-RISK-M02-1086), which statement most accurately defines "Shodan"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A utility for retrieving domain or IP registration and allocation information.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
1087
Module 2 · Applied Domain 4 · Tools / Systems / Programs Shodan Unanswered

During an e-commerce application review (ECOM-WEB-M02-1087), which statement most accurately defines "Shodan"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A utility for retrieving domain or IP registration and allocation information.
Practice
1088
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a manufacturing and OT security review (MFG-OT-M02-1088), which statement most accurately defines "Shodan"?

View answer choices
  1. A utility for retrieving domain or IP registration and allocation information.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
1089
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a mobile-services penetration test (MOB-TEST-M02-1089), which statement most accurately defines "Shodan"?

View answer choices
  1. A search service that indexes Internet-connected devices and service banners.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A utility for retrieving domain or IP registration and allocation information.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
1090
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M02-1090), which statement most accurately defines "Shodan"?

View answer choices
  1. A search service that indexes Internet-connected devices and service banners.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A utility for retrieving domain or IP registration and allocation information.
Practice
1091
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Shodan Unanswered

During an authorized retail-company assessment (RET-LAB-M02-1091), which risk is most directly associated with "Shodan"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Registration metadata can support infrastructure mapping and impersonation.
  3. Automated modules can query third parties or collect data outside scope.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
1092
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a hospital incident-response exercise (HLT-SOC-M02-1092), which risk is most directly associated with "Shodan"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Automated modules can query third parties or collect data outside scope.
  3. Registration metadata can support infrastructure mapping and impersonation.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
1093
Module 2 · Foundation Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a university cyber-range engagement (EDU-RANGE-M02-1093), which risk is most directly associated with "Shodan"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Registration metadata can support infrastructure mapping and impersonation.
  4. Automated modules can query third parties or collect data outside scope.
Practice
1094
Module 2 · Applied Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a financial-services purple-team test (FIN-PT-M02-1094), which risk is most directly associated with "Shodan"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Automated modules can query third parties or collect data outside scope.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Registration metadata can support infrastructure mapping and impersonation.
Practice
1095
Module 2 · Applied Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a cloud startup security audit (CLD-AUDIT-M02-1095), which risk is most directly associated with "Shodan"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Automated modules can query third parties or collect data outside scope.
  3. Registration metadata can support infrastructure mapping and impersonation.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
1096
Module 2 · Applied Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a government risk-validation project (GOV-RISK-M02-1096), which risk is most directly associated with "Shodan"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Automated modules can query third parties or collect data outside scope.
  3. Registration metadata can support infrastructure mapping and impersonation.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
1097
Module 2 · Applied Domain 4 · Tools / Systems / Programs Shodan Unanswered

During an e-commerce application review (ECOM-WEB-M02-1097), which risk is most directly associated with "Shodan"?

View answer choices
  1. Registration metadata can support infrastructure mapping and impersonation.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Automated modules can query third parties or collect data outside scope.
Practice
1098
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a manufacturing and OT security review (MFG-OT-M02-1098), which risk is most directly associated with "Shodan"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Automated modules can query third parties or collect data outside scope.
  4. Registration metadata can support infrastructure mapping and impersonation.
Practice
1099
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a mobile-services penetration test (MOB-TEST-M02-1099), which risk is most directly associated with "Shodan"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Automated modules can query third parties or collect data outside scope.
  3. Registration metadata can support infrastructure mapping and impersonation.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
1100
Module 2 · Advanced Domain 4 · Tools / Systems / Programs Shodan Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M02-1100), which risk is most directly associated with "Shodan"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Registration metadata can support infrastructure mapping and impersonation.
  3. Automated modules can query third parties or collect data outside scope.
  4. Combining public data can expose relationships that were not obvious individually.
Practice