CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 1,501–1,550 of 5,000 matching questions

50 per page
1501
Module 3 · Foundation Domain 4 · Tools / Systems / Programs Nmap Unanswered

During an authorized retail-company assessment (RET-LAB-M03-1501), which action most directly controls the risk related to "Nmap"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Set authorized targets, timing, and scan types before use.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
1502
Module 3 · Foundation Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a hospital incident-response exercise (HLT-SOC-M03-1502), which action most directly controls the risk related to "Nmap"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Set authorized targets, timing, and scan types before use.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
1503
Module 3 · Foundation Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a university cyber-range engagement (EDU-RANGE-M03-1503), which action most directly controls the risk related to "Nmap"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Set authorized targets, timing, and scan types before use.
Practice
1504
Module 3 · Applied Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a financial-services purple-team test (FIN-PT-M03-1504), which action most directly controls the risk related to "Nmap"?

View answer choices
  1. Set authorized targets, timing, and scan types before use.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
1505
Module 3 · Applied Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a cloud startup security audit (CLD-AUDIT-M03-1505), which action most directly controls the risk related to "Nmap"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Set authorized targets, timing, and scan types before use.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
1506
Module 3 · Applied Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a government risk-validation project (GOV-RISK-M03-1506), which action most directly controls the risk related to "Nmap"?

View answer choices
  1. Set authorized targets, timing, and scan types before use.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
1507
Module 3 · Applied Domain 4 · Tools / Systems / Programs Nmap Unanswered

During an e-commerce application review (ECOM-WEB-M03-1507), which action most directly controls the risk related to "Nmap"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Set authorized targets, timing, and scan types before use.
Practice
1508
Module 3 · Advanced Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a manufacturing and OT security review (MFG-OT-M03-1508), which action most directly controls the risk related to "Nmap"?

View answer choices
  1. Set authorized targets, timing, and scan types before use.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
1509
Module 3 · Advanced Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a mobile-services penetration test (MOB-TEST-M03-1509), which action most directly controls the risk related to "Nmap"?

View answer choices
  1. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  2. Set authorized targets, timing, and scan types before use.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
1510
Module 3 · Advanced Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M03-1510), which action most directly controls the risk related to "Nmap"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Set authorized targets, timing, and scan types before use.
Practice
1511
Module 3 · Foundation Domain 4 · Tools / Systems / Programs Nmap Unanswered

During an authorized retail-company assessment (RET-LAB-M03-1511), which evidence best supports an assessment of "Nmap"?

View answer choices
  1. Nmap output correlated with packet capture and target-side service inventory.
  2. A relationship graph retaining sources and transformation history.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Search results validated against the organization’s current external inventory.
Practice
1512
Module 3 · Foundation Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a hospital incident-response exercise (HLT-SOC-M03-1512), which evidence best supports an assessment of "Nmap"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Nmap output correlated with packet capture and target-side service inventory.
  3. Search results validated against the organization’s current external inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
1513
Module 3 · Foundation Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a university cyber-range engagement (EDU-RANGE-M03-1513), which evidence best supports an assessment of "Nmap"?

View answer choices
  1. Nmap output correlated with packet capture and target-side service inventory.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A relationship graph retaining sources and transformation history.
Practice
1514
Module 3 · Applied Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a financial-services purple-team test (FIN-PT-M03-1514), which evidence best supports an assessment of "Nmap"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Nmap output correlated with packet capture and target-side service inventory.
Practice
1515
Module 3 · Applied Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a cloud startup security audit (CLD-AUDIT-M03-1515), which evidence best supports an assessment of "Nmap"?

View answer choices
  1. Nmap output correlated with packet capture and target-side service inventory.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. A relationship graph retaining sources and transformation history.
  4. Search results validated against the organization’s current external inventory.
Practice
1516
Module 3 · Applied Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a government risk-validation project (GOV-RISK-M03-1516), which evidence best supports an assessment of "Nmap"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. Nmap output correlated with packet capture and target-side service inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
1517
Module 3 · Applied Domain 4 · Tools / Systems / Programs Nmap Unanswered

During an e-commerce application review (ECOM-WEB-M03-1517), which evidence best supports an assessment of "Nmap"?

View answer choices
  1. Nmap output correlated with packet capture and target-side service inventory.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A relationship graph retaining sources and transformation history.
Practice
1518
Module 3 · Advanced Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a manufacturing and OT security review (MFG-OT-M03-1518), which evidence best supports an assessment of "Nmap"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. Search results validated against the organization’s current external inventory.
  3. A relationship graph retaining sources and transformation history.
  4. Nmap output correlated with packet capture and target-side service inventory.
Practice
1519
Module 3 · Advanced Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a mobile-services penetration test (MOB-TEST-M03-1519), which evidence best supports an assessment of "Nmap"?

View answer choices
  1. Nmap output correlated with packet capture and target-side service inventory.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. A relationship graph retaining sources and transformation history.
  4. Search results validated against the organization’s current external inventory.
Practice
1520
Module 3 · Advanced Domain 4 · Tools / Systems / Programs Nmap Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M03-1520), which evidence best supports an assessment of "Nmap"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Nmap output correlated with packet capture and target-side service inventory.
  3. Search results validated against the organization’s current external inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
1521
Module 4 · Foundation Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During an authorized retail-company assessment (RET-LAB-M04-1521), which statement most accurately defines "SMB enumeration"?

View answer choices
  1. Collection of Windows or Samba shares, users, policies, and host details through SMB-related services.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
1522
Module 4 · Foundation Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a hospital incident-response exercise (HLT-SOC-M04-1522), which statement most accurately defines "SMB enumeration"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Collection of Windows or Samba shares, users, policies, and host details through SMB-related services.
Practice
1523
Module 4 · Foundation Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a university cyber-range engagement (EDU-RANGE-M04-1523), which statement most accurately defines "SMB enumeration"?

View answer choices
  1. Collection of Windows or Samba shares, users, policies, and host details through SMB-related services.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
1524
Module 4 · Applied Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a financial-services purple-team test (FIN-PT-M04-1524), which statement most accurately defines "SMB enumeration"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Collection of Windows or Samba shares, users, policies, and host details through SMB-related services.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
1525
Module 4 · Applied Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a cloud startup security audit (CLD-AUDIT-M04-1525), which statement most accurately defines "SMB enumeration"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Collection of Windows or Samba shares, users, policies, and host details through SMB-related services.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
1526
Module 4 · Applied Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a government risk-validation project (GOV-RISK-M04-1526), which statement most accurately defines "SMB enumeration"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Collection of Windows or Samba shares, users, policies, and host details through SMB-related services.
Practice
1527
Module 4 · Applied Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During an e-commerce application review (ECOM-WEB-M04-1527), which statement most accurately defines "SMB enumeration"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  3. Collection of Windows or Samba shares, users, policies, and host details through SMB-related services.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
1528
Module 4 · Advanced Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a manufacturing and OT security review (MFG-OT-M04-1528), which statement most accurately defines "SMB enumeration"?

View answer choices
  1. Information gathering that directly interacts with target infrastructure or personnel.
  2. Collection of Windows or Samba shares, users, policies, and host details through SMB-related services.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
1529
Module 4 · Advanced Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a mobile-services penetration test (MOB-TEST-M04-1529), which statement most accurately defines "SMB enumeration"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Collection of Windows or Samba shares, users, policies, and host details through SMB-related services.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
1530
Module 4 · Advanced Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M04-1530), which statement most accurately defines "SMB enumeration"?

View answer choices
  1. Collection of Windows or Samba shares, users, policies, and host details through SMB-related services.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
1531
Module 4 · Foundation Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During an authorized retail-company assessment (RET-LAB-M04-1531), which risk is most directly associated with "SMB enumeration"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  3. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  4. Exposed shares or weak access can disclose sensitive data and reusable credentials.
Practice
1532
Module 4 · Foundation Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a hospital incident-response exercise (HLT-SOC-M04-1532), which risk is most directly associated with "SMB enumeration"?

View answer choices
  1. Exposed shares or weak access can disclose sensitive data and reusable credentials.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
Practice
1533
Module 4 · Foundation Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a university cyber-range engagement (EDU-RANGE-M04-1533), which risk is most directly associated with "SMB enumeration"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Exposed shares or weak access can disclose sensitive data and reusable credentials.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
1534
Module 4 · Applied Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a financial-services purple-team test (FIN-PT-M04-1534), which risk is most directly associated with "SMB enumeration"?

View answer choices
  1. Exposed shares or weak access can disclose sensitive data and reusable credentials.
  2. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  3. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
1535
Module 4 · Applied Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a cloud startup security audit (CLD-AUDIT-M04-1535), which risk is most directly associated with "SMB enumeration"?

View answer choices
  1. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  4. Exposed shares or weak access can disclose sensitive data and reusable credentials.
Practice
1536
Module 4 · Applied Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a government risk-validation project (GOV-RISK-M04-1536), which risk is most directly associated with "SMB enumeration"?

View answer choices
  1. Exposed shares or weak access can disclose sensitive data and reusable credentials.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
Practice
1537
Module 4 · Applied Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During an e-commerce application review (ECOM-WEB-M04-1537), which risk is most directly associated with "SMB enumeration"?

View answer choices
  1. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  2. Exposed shares or weak access can disclose sensitive data and reusable credentials.
  3. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
1538
Module 4 · Advanced Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a manufacturing and OT security review (MFG-OT-M04-1538), which risk is most directly associated with "SMB enumeration"?

View answer choices
  1. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  2. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  3. Exposed shares or weak access can disclose sensitive data and reusable credentials.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
1539
Module 4 · Advanced Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a mobile-services penetration test (MOB-TEST-M04-1539), which risk is most directly associated with "SMB enumeration"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  3. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  4. Exposed shares or weak access can disclose sensitive data and reusable credentials.
Practice
1540
Module 4 · Advanced Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M04-1540), which risk is most directly associated with "SMB enumeration"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Exposed shares or weak access can disclose sensitive data and reusable credentials.
  3. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
1541
Module 4 · Foundation Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During an authorized retail-company assessment (RET-LAB-M04-1541), which action most directly controls the risk related to "SMB enumeration"?

View answer choices
  1. Disable obsolete SMB, restrict access, sign traffic where appropriate, and audit shares.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
1542
Module 4 · Foundation Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a hospital incident-response exercise (HLT-SOC-M04-1542), which action most directly controls the risk related to "SMB enumeration"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Disable obsolete SMB, restrict access, sign traffic where appropriate, and audit shares.
Practice
1543
Module 4 · Foundation Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a university cyber-range engagement (EDU-RANGE-M04-1543), which action most directly controls the risk related to "SMB enumeration"?

View answer choices
  1. Disable obsolete SMB, restrict access, sign traffic where appropriate, and audit shares.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  4. Define permitted techniques and rates in the rules of engagement.
Practice
1544
Module 4 · Applied Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a financial-services purple-team test (FIN-PT-M04-1544), which action most directly controls the risk related to "SMB enumeration"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Disable obsolete SMB, restrict access, sign traffic where appropriate, and audit shares.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Use appropriate registration privacy and monitor unauthorized domain changes.
Practice
1545
Module 4 · Applied Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a cloud startup security audit (CLD-AUDIT-M04-1545), which action most directly controls the risk related to "SMB enumeration"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Disable obsolete SMB, restrict access, sign traffic where appropriate, and audit shares.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
1546
Module 4 · Applied Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a government risk-validation project (GOV-RISK-M04-1546), which action most directly controls the risk related to "SMB enumeration"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Disable obsolete SMB, restrict access, sign traffic where appropriate, and audit shares.
Practice
1547
Module 4 · Applied Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During an e-commerce application review (ECOM-WEB-M04-1547), which action most directly controls the risk related to "SMB enumeration"?

View answer choices
  1. Disable obsolete SMB, restrict access, sign traffic where appropriate, and audit shares.
  2. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Define permitted techniques and rates in the rules of engagement.
Practice
1548
Module 4 · Advanced Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a manufacturing and OT security review (MFG-OT-M04-1548), which action most directly controls the risk related to "SMB enumeration"?

View answer choices
  1. Define permitted techniques and rates in the rules of engagement.
  2. Disable obsolete SMB, restrict access, sign traffic where appropriate, and audit shares.
  3. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  4. Use appropriate registration privacy and monitor unauthorized domain changes.
Practice
1549
Module 4 · Advanced Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a mobile-services penetration test (MOB-TEST-M04-1549), which action most directly controls the risk related to "SMB enumeration"?

View answer choices
  1. Disable obsolete SMB, restrict access, sign traffic where appropriate, and audit shares.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
1550
Module 4 · Advanced Domain 2 · Analysis / Assessment SMB enumeration Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M04-1550), which action most directly controls the risk related to "SMB enumeration"?

View answer choices
  1. Disable obsolete SMB, restrict access, sign traffic where appropriate, and audit shares.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  4. Define permitted techniques and rates in the rules of engagement.
Practice