CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 1,701–1,750 of 5,000 matching questions

50 per page
1701
Module 4 · Foundation Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During an authorized retail-company assessment (RET-LAB-M04-1701), which action most directly controls the risk related to "snmpwalk"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Use SNMPv3 and restrict queries to approved management systems.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
1702
Module 4 · Foundation Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a hospital incident-response exercise (HLT-SOC-M04-1702), which action most directly controls the risk related to "snmpwalk"?

View answer choices
  1. Use SNMPv3 and restrict queries to approved management systems.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
1703
Module 4 · Foundation Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a university cyber-range engagement (EDU-RANGE-M04-1703), which action most directly controls the risk related to "snmpwalk"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Use SNMPv3 and restrict queries to approved management systems.
Practice
1704
Module 4 · Applied Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a financial-services purple-team test (FIN-PT-M04-1704), which action most directly controls the risk related to "snmpwalk"?

View answer choices
  1. Use SNMPv3 and restrict queries to approved management systems.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
1705
Module 4 · Applied Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a cloud startup security audit (CLD-AUDIT-M04-1705), which action most directly controls the risk related to "snmpwalk"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Use SNMPv3 and restrict queries to approved management systems.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
1706
Module 4 · Applied Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a government risk-validation project (GOV-RISK-M04-1706), which action most directly controls the risk related to "snmpwalk"?

View answer choices
  1. Use SNMPv3 and restrict queries to approved management systems.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
1707
Module 4 · Applied Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During an e-commerce application review (ECOM-WEB-M04-1707), which action most directly controls the risk related to "snmpwalk"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Use SNMPv3 and restrict queries to approved management systems.
Practice
1708
Module 4 · Advanced Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a manufacturing and OT security review (MFG-OT-M04-1708), which action most directly controls the risk related to "snmpwalk"?

View answer choices
  1. Use SNMPv3 and restrict queries to approved management systems.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
1709
Module 4 · Advanced Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a mobile-services penetration test (MOB-TEST-M04-1709), which action most directly controls the risk related to "snmpwalk"?

View answer choices
  1. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  2. Use SNMPv3 and restrict queries to approved management systems.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
1710
Module 4 · Advanced Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M04-1710), which action most directly controls the risk related to "snmpwalk"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Use SNMPv3 and restrict queries to approved management systems.
Practice
1711
Module 4 · Foundation Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During an authorized retail-company assessment (RET-LAB-M04-1711), which evidence best supports an assessment of "snmpwalk"?

View answer choices
  1. OID results showing the SNMP version, identity, and authorized query source.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. A relationship graph retaining sources and transformation history.
  4. Search results validated against the organization’s current external inventory.
Practice
1712
Module 4 · Foundation Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a hospital incident-response exercise (HLT-SOC-M04-1712), which evidence best supports an assessment of "snmpwalk"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. OID results showing the SNMP version, identity, and authorized query source.
  3. Search results validated against the organization’s current external inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
1713
Module 4 · Foundation Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a university cyber-range engagement (EDU-RANGE-M04-1713), which evidence best supports an assessment of "snmpwalk"?

View answer choices
  1. OID results showing the SNMP version, identity, and authorized query source.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. Search results validated against the organization’s current external inventory.
  4. A relationship graph retaining sources and transformation history.
Practice
1714
Module 4 · Applied Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a financial-services purple-team test (FIN-PT-M04-1714), which evidence best supports an assessment of "snmpwalk"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. OID results showing the SNMP version, identity, and authorized query source.
Practice
1715
Module 4 · Applied Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a cloud startup security audit (CLD-AUDIT-M04-1715), which evidence best supports an assessment of "snmpwalk"?

View answer choices
  1. OID results showing the SNMP version, identity, and authorized query source.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. A relationship graph retaining sources and transformation history.
  4. Search results validated against the organization’s current external inventory.
Practice
1716
Module 4 · Applied Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a government risk-validation project (GOV-RISK-M04-1716), which evidence best supports an assessment of "snmpwalk"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. OID results showing the SNMP version, identity, and authorized query source.
  3. Search results validated against the organization’s current external inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
1717
Module 4 · Applied Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During an e-commerce application review (ECOM-WEB-M04-1717), which evidence best supports an assessment of "snmpwalk"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. Search results validated against the organization’s current external inventory.
  3. OID results showing the SNMP version, identity, and authorized query source.
  4. A relationship graph retaining sources and transformation history.
Practice
1718
Module 4 · Advanced Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a manufacturing and OT security review (MFG-OT-M04-1718), which evidence best supports an assessment of "snmpwalk"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. Search results validated against the organization’s current external inventory.
  3. A relationship graph retaining sources and transformation history.
  4. OID results showing the SNMP version, identity, and authorized query source.
Practice
1719
Module 4 · Advanced Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a mobile-services penetration test (MOB-TEST-M04-1719), which evidence best supports an assessment of "snmpwalk"?

View answer choices
  1. OID results showing the SNMP version, identity, and authorized query source.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. A relationship graph retaining sources and transformation history.
  4. Search results validated against the organization’s current external inventory.
Practice
1720
Module 4 · Advanced Domain 4 · Tools / Systems / Programs snmpwalk Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M04-1720), which evidence best supports an assessment of "snmpwalk"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. OID results showing the SNMP version, identity, and authorized query source.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
1721
Module 5 · Foundation Domain 2 · Analysis / Assessment CVSS Unanswered

During an authorized retail-company assessment (RET-LAB-M05-1721), which statement most accurately defines "CVSS"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. A standardized framework for expressing characteristics that influence vulnerability severity.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
1722
Module 5 · Foundation Domain 2 · Analysis / Assessment CVSS Unanswered

During a hospital incident-response exercise (HLT-SOC-M05-1722), which statement most accurately defines "CVSS"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  4. A standardized framework for expressing characteristics that influence vulnerability severity.
Practice
1723
Module 5 · Foundation Domain 2 · Analysis / Assessment CVSS Unanswered

During a university cyber-range engagement (EDU-RANGE-M05-1723), which statement most accurately defines "CVSS"?

View answer choices
  1. A standardized framework for expressing characteristics that influence vulnerability severity.
  2. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  3. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
1724
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During a financial-services purple-team test (FIN-PT-M05-1724), which statement most accurately defines "CVSS"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. A standardized framework for expressing characteristics that influence vulnerability severity.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
1725
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During a cloud startup security audit (CLD-AUDIT-M05-1725), which statement most accurately defines "CVSS"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. A standardized framework for expressing characteristics that influence vulnerability severity.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
1726
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During a government risk-validation project (GOV-RISK-M05-1726), which statement most accurately defines "CVSS"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. A standardized framework for expressing characteristics that influence vulnerability severity.
Practice
1727
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During an e-commerce application review (ECOM-WEB-M05-1727), which statement most accurately defines "CVSS"?

View answer choices
  1. A standardized framework for expressing characteristics that influence vulnerability severity.
  2. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  3. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
1728
Module 5 · Advanced Domain 2 · Analysis / Assessment CVSS Unanswered

During a manufacturing and OT security review (MFG-OT-M05-1728), which statement most accurately defines "CVSS"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. A standardized framework for expressing characteristics that influence vulnerability severity.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
1729
Module 5 · Advanced Domain 2 · Analysis / Assessment CVSS Unanswered

During a mobile-services penetration test (MOB-TEST-M05-1729), which statement most accurately defines "CVSS"?

View answer choices
  1. A standardized framework for expressing characteristics that influence vulnerability severity.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
1730
Module 5 · Advanced Domain 2 · Analysis / Assessment CVSS Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M05-1730), which statement most accurately defines "CVSS"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  3. A standardized framework for expressing characteristics that influence vulnerability severity.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
1731
Module 5 · Foundation Domain 2 · Analysis / Assessment CVSS Unanswered

During an authorized retail-company assessment (RET-LAB-M05-1731), which risk is most directly associated with "CVSS"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  3. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  4. Treating a base score as business risk can misprioritize remediation.
Practice
1732
Module 5 · Foundation Domain 2 · Analysis / Assessment CVSS Unanswered

During a hospital incident-response exercise (HLT-SOC-M05-1732), which risk is most directly associated with "CVSS"?

View answer choices
  1. Treating a base score as business risk can misprioritize remediation.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
Practice
1733
Module 5 · Foundation Domain 2 · Analysis / Assessment CVSS Unanswered

During a university cyber-range engagement (EDU-RANGE-M05-1733), which risk is most directly associated with "CVSS"?

View answer choices
  1. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  2. Treating a base score as business risk can misprioritize remediation.
  3. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
1734
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During a financial-services purple-team test (FIN-PT-M05-1734), which risk is most directly associated with "CVSS"?

View answer choices
  1. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  2. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  3. Treating a base score as business risk can misprioritize remediation.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
1735
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During a cloud startup security audit (CLD-AUDIT-M05-1735), which risk is most directly associated with "CVSS"?

View answer choices
  1. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  4. Treating a base score as business risk can misprioritize remediation.
Practice
1736
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During a government risk-validation project (GOV-RISK-M05-1736), which risk is most directly associated with "CVSS"?

View answer choices
  1. Treating a base score as business risk can misprioritize remediation.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
Practice
1737
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During an e-commerce application review (ECOM-WEB-M05-1737), which risk is most directly associated with "CVSS"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Treating a base score as business risk can misprioritize remediation.
  3. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
1738
Module 5 · Advanced Domain 2 · Analysis / Assessment CVSS Unanswered

During a manufacturing and OT security review (MFG-OT-M05-1738), which risk is most directly associated with "CVSS"?

View answer choices
  1. Treating a base score as business risk can misprioritize remediation.
  2. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
1739
Module 5 · Advanced Domain 2 · Analysis / Assessment CVSS Unanswered

During a mobile-services penetration test (MOB-TEST-M05-1739), which risk is most directly associated with "CVSS"?

View answer choices
  1. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  4. Treating a base score as business risk can misprioritize remediation.
Practice
1740
Module 5 · Advanced Domain 2 · Analysis / Assessment CVSS Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M05-1740), which risk is most directly associated with "CVSS"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Treating a base score as business risk can misprioritize remediation.
  3. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
1741
Module 5 · Foundation Domain 2 · Analysis / Assessment CVSS Unanswered

During an authorized retail-company assessment (RET-LAB-M05-1741), which action most directly controls the risk related to "CVSS"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Combine CVSS metrics with exploitability, exposure, asset value, and compensating controls.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
1742
Module 5 · Foundation Domain 2 · Analysis / Assessment CVSS Unanswered

During a hospital incident-response exercise (HLT-SOC-M05-1742), which action most directly controls the risk related to "CVSS"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Use appropriate registration privacy and monitor unauthorized domain changes.
  4. Combine CVSS metrics with exploitability, exposure, asset value, and compensating controls.
Practice
1743
Module 5 · Foundation Domain 2 · Analysis / Assessment CVSS Unanswered

During a university cyber-range engagement (EDU-RANGE-M05-1743), which action most directly controls the risk related to "CVSS"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  3. Combine CVSS metrics with exploitability, exposure, asset value, and compensating controls.
  4. Define permitted techniques and rates in the rules of engagement.
Practice
1744
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During a financial-services purple-team test (FIN-PT-M05-1744), which action most directly controls the risk related to "CVSS"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Combine CVSS metrics with exploitability, exposure, asset value, and compensating controls.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Use appropriate registration privacy and monitor unauthorized domain changes.
Practice
1745
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During a cloud startup security audit (CLD-AUDIT-M05-1745), which action most directly controls the risk related to "CVSS"?

View answer choices
  1. Combine CVSS metrics with exploitability, exposure, asset value, and compensating controls.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
1746
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During a government risk-validation project (GOV-RISK-M05-1746), which action most directly controls the risk related to "CVSS"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Combine CVSS metrics with exploitability, exposure, asset value, and compensating controls.
Practice
1747
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During an e-commerce application review (ECOM-WEB-M05-1747), which action most directly controls the risk related to "CVSS"?

View answer choices
  1. Combine CVSS metrics with exploitability, exposure, asset value, and compensating controls.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  4. Define permitted techniques and rates in the rules of engagement.
Practice
1748
Module 5 · Advanced Domain 2 · Analysis / Assessment CVSS Unanswered

During a manufacturing and OT security review (MFG-OT-M05-1748), which action most directly controls the risk related to "CVSS"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Combine CVSS metrics with exploitability, exposure, asset value, and compensating controls.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Use appropriate registration privacy and monitor unauthorized domain changes.
Practice
1749
Module 5 · Advanced Domain 2 · Analysis / Assessment CVSS Unanswered

During a mobile-services penetration test (MOB-TEST-M05-1749), which action most directly controls the risk related to "CVSS"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Combine CVSS metrics with exploitability, exposure, asset value, and compensating controls.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
1750
Module 5 · Advanced Domain 2 · Analysis / Assessment CVSS Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M05-1750), which action most directly controls the risk related to "CVSS"?

View answer choices
  1. Combine CVSS metrics with exploitability, exposure, asset value, and compensating controls.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  4. Define permitted techniques and rates in the rules of engagement.
Practice