CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 1,301–1,350 of 5,000 matching questions

50 per page
1301
Module 3 · Foundation Domain 2 · Analysis / Assessment host discovery Unanswered

During an authorized retail-company assessment (RET-LAB-M03-1301), which action most directly controls the risk related to "host discovery"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Monitor sweeps, restrict unnecessary responses, and segment management networks.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Use appropriate registration privacy and monitor unauthorized domain changes.
Practice
1302
Module 3 · Foundation Domain 2 · Analysis / Assessment host discovery Unanswered

During a hospital incident-response exercise (HLT-SOC-M03-1302), which action most directly controls the risk related to "host discovery"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  3. Monitor sweeps, restrict unnecessary responses, and segment management networks.
  4. Define permitted techniques and rates in the rules of engagement.
Practice
1303
Module 3 · Foundation Domain 2 · Analysis / Assessment host discovery Unanswered

During a university cyber-range engagement (EDU-RANGE-M03-1303), which action most directly controls the risk related to "host discovery"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Monitor sweeps, restrict unnecessary responses, and segment management networks.
Practice
1304
Module 3 · Applied Domain 2 · Analysis / Assessment host discovery Unanswered

During a financial-services purple-team test (FIN-PT-M03-1304), which action most directly controls the risk related to "host discovery"?

View answer choices
  1. Monitor sweeps, restrict unnecessary responses, and segment management networks.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
1305
Module 3 · Applied Domain 2 · Analysis / Assessment host discovery Unanswered

During a cloud startup security audit (CLD-AUDIT-M03-1305), which action most directly controls the risk related to "host discovery"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Monitor sweeps, restrict unnecessary responses, and segment management networks.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Use appropriate registration privacy and monitor unauthorized domain changes.
Practice
1306
Module 3 · Applied Domain 2 · Analysis / Assessment host discovery Unanswered

During a government risk-validation project (GOV-RISK-M03-1306), which action most directly controls the risk related to "host discovery"?

View answer choices
  1. Monitor sweeps, restrict unnecessary responses, and segment management networks.
  2. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Define permitted techniques and rates in the rules of engagement.
Practice
1307
Module 3 · Applied Domain 2 · Analysis / Assessment host discovery Unanswered

During an e-commerce application review (ECOM-WEB-M03-1307), which action most directly controls the risk related to "host discovery"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  4. Monitor sweeps, restrict unnecessary responses, and segment management networks.
Practice
1308
Module 3 · Advanced Domain 2 · Analysis / Assessment host discovery Unanswered

During a manufacturing and OT security review (MFG-OT-M03-1308), which action most directly controls the risk related to "host discovery"?

View answer choices
  1. Monitor sweeps, restrict unnecessary responses, and segment management networks.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
1309
Module 3 · Advanced Domain 2 · Analysis / Assessment host discovery Unanswered

During a mobile-services penetration test (MOB-TEST-M03-1309), which action most directly controls the risk related to "host discovery"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Monitor sweeps, restrict unnecessary responses, and segment management networks.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Use appropriate registration privacy and monitor unauthorized domain changes.
Practice
1310
Module 3 · Advanced Domain 2 · Analysis / Assessment host discovery Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M03-1310), which action most directly controls the risk related to "host discovery"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Monitor sweeps, restrict unnecessary responses, and segment management networks.
Practice
1311
Module 3 · Foundation Domain 2 · Analysis / Assessment host discovery Unanswered

During an authorized retail-company assessment (RET-LAB-M03-1311), which evidence best supports an assessment of "host discovery"?

View answer choices
  1. Correlated ARP, ICMP, TCP, or UDP responses establishing host reachability.
  2. Authoritative DNS responses and a validated map of relevant record types.
  3. Registrar records showing nameservers, dates, status codes, and registration contacts.
  4. Timestamped probe logs matched to the approved source and scope.
Practice
1312
Module 3 · Foundation Domain 2 · Analysis / Assessment host discovery Unanswered

During a hospital incident-response exercise (HLT-SOC-M03-1312), which evidence best supports an assessment of "host discovery"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Correlated ARP, ICMP, TCP, or UDP responses establishing host reachability.
  3. Timestamped probe logs matched to the approved source and scope.
  4. Registrar records showing nameservers, dates, status codes, and registration contacts.
Practice
1313
Module 3 · Foundation Domain 2 · Analysis / Assessment host discovery Unanswered

During a university cyber-range engagement (EDU-RANGE-M03-1313), which evidence best supports an assessment of "host discovery"?

View answer choices
  1. Correlated ARP, ICMP, TCP, or UDP responses establishing host reachability.
  2. Registrar records showing nameservers, dates, status codes, and registration contacts.
  3. Timestamped probe logs matched to the approved source and scope.
  4. Authoritative DNS responses and a validated map of relevant record types.
Practice
1314
Module 3 · Applied Domain 2 · Analysis / Assessment host discovery Unanswered

During a financial-services purple-team test (FIN-PT-M03-1314), which evidence best supports an assessment of "host discovery"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Registrar records showing nameservers, dates, status codes, and registration contacts.
  3. Timestamped probe logs matched to the approved source and scope.
  4. Correlated ARP, ICMP, TCP, or UDP responses establishing host reachability.
Practice
1315
Module 3 · Applied Domain 2 · Analysis / Assessment host discovery Unanswered

During a cloud startup security audit (CLD-AUDIT-M03-1315), which evidence best supports an assessment of "host discovery"?

View answer choices
  1. Registrar records showing nameservers, dates, status codes, and registration contacts.
  2. Authoritative DNS responses and a validated map of relevant record types.
  3. Correlated ARP, ICMP, TCP, or UDP responses establishing host reachability.
  4. Timestamped probe logs matched to the approved source and scope.
Practice
1316
Module 3 · Applied Domain 2 · Analysis / Assessment host discovery Unanswered

During a government risk-validation project (GOV-RISK-M03-1316), which evidence best supports an assessment of "host discovery"?

View answer choices
  1. Timestamped probe logs matched to the approved source and scope.
  2. Correlated ARP, ICMP, TCP, or UDP responses establishing host reachability.
  3. Authoritative DNS responses and a validated map of relevant record types.
  4. Registrar records showing nameservers, dates, status codes, and registration contacts.
Practice
1317
Module 3 · Applied Domain 2 · Analysis / Assessment host discovery Unanswered

During an e-commerce application review (ECOM-WEB-M03-1317), which evidence best supports an assessment of "host discovery"?

View answer choices
  1. Correlated ARP, ICMP, TCP, or UDP responses establishing host reachability.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Registrar records showing nameservers, dates, status codes, and registration contacts.
  4. Authoritative DNS responses and a validated map of relevant record types.
Practice
1318
Module 3 · Advanced Domain 2 · Analysis / Assessment host discovery Unanswered

During a manufacturing and OT security review (MFG-OT-M03-1318), which evidence best supports an assessment of "host discovery"?

View answer choices
  1. Registrar records showing nameservers, dates, status codes, and registration contacts.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Authoritative DNS responses and a validated map of relevant record types.
  4. Correlated ARP, ICMP, TCP, or UDP responses establishing host reachability.
Practice
1319
Module 3 · Advanced Domain 2 · Analysis / Assessment host discovery Unanswered

During a mobile-services penetration test (MOB-TEST-M03-1319), which evidence best supports an assessment of "host discovery"?

View answer choices
  1. Correlated ARP, ICMP, TCP, or UDP responses establishing host reachability.
  2. Registrar records showing nameservers, dates, status codes, and registration contacts.
  3. Authoritative DNS responses and a validated map of relevant record types.
  4. Timestamped probe logs matched to the approved source and scope.
Practice
1320
Module 3 · Advanced Domain 2 · Analysis / Assessment host discovery Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M03-1320), which evidence best supports an assessment of "host discovery"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Correlated ARP, ICMP, TCP, or UDP responses establishing host reachability.
  4. Registrar records showing nameservers, dates, status codes, and registration contacts.
Practice
1321
Module 3 · Foundation Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During an authorized retail-company assessment (RET-LAB-M03-1321), which statement most accurately defines "operating-system fingerprinting"?

View answer choices
  1. Inference of a target operating system from network behavior, protocol characteristics, or banners.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
1322
Module 3 · Foundation Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a hospital incident-response exercise (HLT-SOC-M03-1322), which statement most accurately defines "operating-system fingerprinting"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Inference of a target operating system from network behavior, protocol characteristics, or banners.
Practice
1323
Module 3 · Foundation Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a university cyber-range engagement (EDU-RANGE-M03-1323), which statement most accurately defines "operating-system fingerprinting"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  3. Inference of a target operating system from network behavior, protocol characteristics, or banners.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
1324
Module 3 · Applied Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a financial-services purple-team test (FIN-PT-M03-1324), which statement most accurately defines "operating-system fingerprinting"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Inference of a target operating system from network behavior, protocol characteristics, or banners.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
1325
Module 3 · Applied Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a cloud startup security audit (CLD-AUDIT-M03-1325), which statement most accurately defines "operating-system fingerprinting"?

View answer choices
  1. Inference of a target operating system from network behavior, protocol characteristics, or banners.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
1326
Module 3 · Applied Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a government risk-validation project (GOV-RISK-M03-1326), which statement most accurately defines "operating-system fingerprinting"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Inference of a target operating system from network behavior, protocol characteristics, or banners.
Practice
1327
Module 3 · Applied Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During an e-commerce application review (ECOM-WEB-M03-1327), which statement most accurately defines "operating-system fingerprinting"?

View answer choices
  1. Inference of a target operating system from network behavior, protocol characteristics, or banners.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
1328
Module 3 · Advanced Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a manufacturing and OT security review (MFG-OT-M03-1328), which statement most accurately defines "operating-system fingerprinting"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Inference of a target operating system from network behavior, protocol characteristics, or banners.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
1329
Module 3 · Advanced Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a mobile-services penetration test (MOB-TEST-M03-1329), which statement most accurately defines "operating-system fingerprinting"?

View answer choices
  1. Inference of a target operating system from network behavior, protocol characteristics, or banners.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
1330
Module 3 · Advanced Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M03-1330), which statement most accurately defines "operating-system fingerprinting"?

View answer choices
  1. Inference of a target operating system from network behavior, protocol characteristics, or banners.
  2. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  3. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
1331
Module 3 · Foundation Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During an authorized retail-company assessment (RET-LAB-M03-1331), which risk is most directly associated with "operating-system fingerprinting"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Accurate platform identification narrows likely vulnerabilities and attack techniques.
Practice
1332
Module 3 · Foundation Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a hospital incident-response exercise (HLT-SOC-M03-1332), which risk is most directly associated with "operating-system fingerprinting"?

View answer choices
  1. Accurate platform identification narrows likely vulnerabilities and attack techniques.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
Practice
1333
Module 3 · Foundation Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a university cyber-range engagement (EDU-RANGE-M03-1333), which risk is most directly associated with "operating-system fingerprinting"?

View answer choices
  1. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  2. Accurate platform identification narrows likely vulnerabilities and attack techniques.
  3. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
1334
Module 3 · Applied Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a financial-services purple-team test (FIN-PT-M03-1334), which risk is most directly associated with "operating-system fingerprinting"?

View answer choices
  1. Accurate platform identification narrows likely vulnerabilities and attack techniques.
  2. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
1335
Module 3 · Applied Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a cloud startup security audit (CLD-AUDIT-M03-1335), which risk is most directly associated with "operating-system fingerprinting"?

View answer choices
  1. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  4. Accurate platform identification narrows likely vulnerabilities and attack techniques.
Practice
1336
Module 3 · Applied Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a government risk-validation project (GOV-RISK-M03-1336), which risk is most directly associated with "operating-system fingerprinting"?

View answer choices
  1. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Accurate platform identification narrows likely vulnerabilities and attack techniques.
  4. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
Practice
1337
Module 3 · Applied Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During an e-commerce application review (ECOM-WEB-M03-1337), which risk is most directly associated with "operating-system fingerprinting"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Accurate platform identification narrows likely vulnerabilities and attack techniques.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
1338
Module 3 · Advanced Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a manufacturing and OT security review (MFG-OT-M03-1338), which risk is most directly associated with "operating-system fingerprinting"?

View answer choices
  1. Accurate platform identification narrows likely vulnerabilities and attack techniques.
  2. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  3. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
1339
Module 3 · Advanced Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a mobile-services penetration test (MOB-TEST-M03-1339), which risk is most directly associated with "operating-system fingerprinting"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  3. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  4. Accurate platform identification narrows likely vulnerabilities and attack techniques.
Practice
1340
Module 3 · Advanced Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M03-1340), which risk is most directly associated with "operating-system fingerprinting"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Accurate platform identification narrows likely vulnerabilities and attack techniques.
  3. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
1341
Module 3 · Foundation Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During an authorized retail-company assessment (RET-LAB-M03-1341), which action most directly controls the risk related to "operating-system fingerprinting"?

View answer choices
  1. Normalize externally visible behavior where practical and keep platforms patched.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
1342
Module 3 · Foundation Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a hospital incident-response exercise (HLT-SOC-M03-1342), which action most directly controls the risk related to "operating-system fingerprinting"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Normalize externally visible behavior where practical and keep platforms patched.
Practice
1343
Module 3 · Foundation Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a university cyber-range engagement (EDU-RANGE-M03-1343), which action most directly controls the risk related to "operating-system fingerprinting"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  3. Normalize externally visible behavior where practical and keep platforms patched.
  4. Define permitted techniques and rates in the rules of engagement.
Practice
1344
Module 3 · Applied Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a financial-services purple-team test (FIN-PT-M03-1344), which action most directly controls the risk related to "operating-system fingerprinting"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Normalize externally visible behavior where practical and keep platforms patched.
  4. Use appropriate registration privacy and monitor unauthorized domain changes.
Practice
1345
Module 3 · Applied Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a cloud startup security audit (CLD-AUDIT-M03-1345), which action most directly controls the risk related to "operating-system fingerprinting"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Normalize externally visible behavior where practical and keep platforms patched.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
1346
Module 3 · Applied Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a government risk-validation project (GOV-RISK-M03-1346), which action most directly controls the risk related to "operating-system fingerprinting"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Normalize externally visible behavior where practical and keep platforms patched.
Practice
1347
Module 3 · Applied Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During an e-commerce application review (ECOM-WEB-M03-1347), which action most directly controls the risk related to "operating-system fingerprinting"?

View answer choices
  1. Normalize externally visible behavior where practical and keep platforms patched.
  2. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Define permitted techniques and rates in the rules of engagement.
Practice
1348
Module 3 · Advanced Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a manufacturing and OT security review (MFG-OT-M03-1348), which action most directly controls the risk related to "operating-system fingerprinting"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Normalize externally visible behavior where practical and keep platforms patched.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Use appropriate registration privacy and monitor unauthorized domain changes.
Practice
1349
Module 3 · Advanced Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a mobile-services penetration test (MOB-TEST-M03-1349), which action most directly controls the risk related to "operating-system fingerprinting"?

View answer choices
  1. Normalize externally visible behavior where practical and keep platforms patched.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
1350
Module 3 · Advanced Domain 2 · Analysis / Assessment operating-system fingerprinting Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M03-1350), which action most directly controls the risk related to "operating-system fingerprinting"?

View answer choices
  1. Normalize externally visible behavior where practical and keep platforms patched.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  4. Define permitted techniques and rates in the rules of engagement.
Practice