CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 1,751–1,800 of 5,000 matching questions

50 per page
1751
Module 5 · Foundation Domain 2 · Analysis / Assessment CVSS Unanswered

During an authorized retail-company assessment (RET-LAB-M05-1751), which evidence best supports an assessment of "CVSS"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Registrar records showing nameservers, dates, status codes, and registration contacts.
  4. A documented vector string plus environmental context and final prioritization rationale.
Practice
1752
Module 5 · Foundation Domain 2 · Analysis / Assessment CVSS Unanswered

During a hospital incident-response exercise (HLT-SOC-M05-1752), which evidence best supports an assessment of "CVSS"?

View answer choices
  1. A documented vector string plus environmental context and final prioritization rationale.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Registrar records showing nameservers, dates, status codes, and registration contacts.
  4. Authoritative DNS responses and a validated map of relevant record types.
Practice
1753
Module 5 · Foundation Domain 2 · Analysis / Assessment CVSS Unanswered

During a university cyber-range engagement (EDU-RANGE-M05-1753), which evidence best supports an assessment of "CVSS"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Timestamped probe logs matched to the approved source and scope.
  3. A documented vector string plus environmental context and final prioritization rationale.
  4. Registrar records showing nameservers, dates, status codes, and registration contacts.
Practice
1754
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During a financial-services purple-team test (FIN-PT-M05-1754), which evidence best supports an assessment of "CVSS"?

View answer choices
  1. A documented vector string plus environmental context and final prioritization rationale.
  2. Authoritative DNS responses and a validated map of relevant record types.
  3. Registrar records showing nameservers, dates, status codes, and registration contacts.
  4. Timestamped probe logs matched to the approved source and scope.
Practice
1755
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During a cloud startup security audit (CLD-AUDIT-M05-1755), which evidence best supports an assessment of "CVSS"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Registrar records showing nameservers, dates, status codes, and registration contacts.
  3. Timestamped probe logs matched to the approved source and scope.
  4. A documented vector string plus environmental context and final prioritization rationale.
Practice
1756
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During a government risk-validation project (GOV-RISK-M05-1756), which evidence best supports an assessment of "CVSS"?

View answer choices
  1. Registrar records showing nameservers, dates, status codes, and registration contacts.
  2. Timestamped probe logs matched to the approved source and scope.
  3. A documented vector string plus environmental context and final prioritization rationale.
  4. Authoritative DNS responses and a validated map of relevant record types.
Practice
1757
Module 5 · Applied Domain 2 · Analysis / Assessment CVSS Unanswered

During an e-commerce application review (ECOM-WEB-M05-1757), which evidence best supports an assessment of "CVSS"?

View answer choices
  1. Timestamped probe logs matched to the approved source and scope.
  2. A documented vector string plus environmental context and final prioritization rationale.
  3. Authoritative DNS responses and a validated map of relevant record types.
  4. Registrar records showing nameservers, dates, status codes, and registration contacts.
Practice
1758
Module 5 · Advanced Domain 2 · Analysis / Assessment CVSS Unanswered

During a manufacturing and OT security review (MFG-OT-M05-1758), which evidence best supports an assessment of "CVSS"?

View answer choices
  1. A documented vector string plus environmental context and final prioritization rationale.
  2. Registrar records showing nameservers, dates, status codes, and registration contacts.
  3. Authoritative DNS responses and a validated map of relevant record types.
  4. Timestamped probe logs matched to the approved source and scope.
Practice
1759
Module 5 · Advanced Domain 2 · Analysis / Assessment CVSS Unanswered

During a mobile-services penetration test (MOB-TEST-M05-1759), which evidence best supports an assessment of "CVSS"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Registrar records showing nameservers, dates, status codes, and registration contacts.
  4. A documented vector string plus environmental context and final prioritization rationale.
Practice
1760
Module 5 · Advanced Domain 2 · Analysis / Assessment CVSS Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M05-1760), which evidence best supports an assessment of "CVSS"?

View answer choices
  1. A documented vector string plus environmental context and final prioritization rationale.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Registrar records showing nameservers, dates, status codes, and registration contacts.
  4. Authoritative DNS responses and a validated map of relevant record types.
Practice
1761
Module 5 · Foundation Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During an authorized retail-company assessment (RET-LAB-M05-1761), which statement most accurately defines "vulnerability assessment"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Systematic identification and prioritization of weaknesses without necessarily exploiting them.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
1762
Module 5 · Foundation Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a hospital incident-response exercise (HLT-SOC-M05-1762), which statement most accurately defines "vulnerability assessment"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  3. Systematic identification and prioritization of weaknesses without necessarily exploiting them.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
1763
Module 5 · Foundation Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a university cyber-range engagement (EDU-RANGE-M05-1763), which statement most accurately defines "vulnerability assessment"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Systematic identification and prioritization of weaknesses without necessarily exploiting them.
Practice
1764
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a financial-services purple-team test (FIN-PT-M05-1764), which statement most accurately defines "vulnerability assessment"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Systematic identification and prioritization of weaknesses without necessarily exploiting them.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
1765
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a cloud startup security audit (CLD-AUDIT-M05-1765), which statement most accurately defines "vulnerability assessment"?

View answer choices
  1. Information gathering that directly interacts with target infrastructure or personnel.
  2. Systematic identification and prioritization of weaknesses without necessarily exploiting them.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
1766
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a government risk-validation project (GOV-RISK-M05-1766), which statement most accurately defines "vulnerability assessment"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  3. Systematic identification and prioritization of weaknesses without necessarily exploiting them.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
1767
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During an e-commerce application review (ECOM-WEB-M05-1767), which statement most accurately defines "vulnerability assessment"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Systematic identification and prioritization of weaknesses without necessarily exploiting them.
Practice
1768
Module 5 · Advanced Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a manufacturing and OT security review (MFG-OT-M05-1768), which statement most accurately defines "vulnerability assessment"?

View answer choices
  1. Systematic identification and prioritization of weaknesses without necessarily exploiting them.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
1769
Module 5 · Advanced Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a mobile-services penetration test (MOB-TEST-M05-1769), which statement most accurately defines "vulnerability assessment"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Systematic identification and prioritization of weaknesses without necessarily exploiting them.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
1770
Module 5 · Advanced Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M05-1770), which statement most accurately defines "vulnerability assessment"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  4. Systematic identification and prioritization of weaknesses without necessarily exploiting them.
Practice
1771
Module 5 · Foundation Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During an authorized retail-company assessment (RET-LAB-M05-1771), which risk is most directly associated with "vulnerability assessment"?

View answer choices
  1. Unvalidated scanner output can create false confidence or waste remediation effort.
  2. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
1772
Module 5 · Foundation Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a hospital incident-response exercise (HLT-SOC-M05-1772), which risk is most directly associated with "vulnerability assessment"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Unvalidated scanner output can create false confidence or waste remediation effort.
  3. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
1773
Module 5 · Foundation Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a university cyber-range engagement (EDU-RANGE-M05-1773), which risk is most directly associated with "vulnerability assessment"?

View answer choices
  1. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Unvalidated scanner output can create false confidence or waste remediation effort.
  4. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
Practice
1774
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a financial-services purple-team test (FIN-PT-M05-1774), which risk is most directly associated with "vulnerability assessment"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Unvalidated scanner output can create false confidence or waste remediation effort.
Practice
1775
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a cloud startup security audit (CLD-AUDIT-M05-1775), which risk is most directly associated with "vulnerability assessment"?

View answer choices
  1. Unvalidated scanner output can create false confidence or waste remediation effort.
  2. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  3. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
1776
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a government risk-validation project (GOV-RISK-M05-1776), which risk is most directly associated with "vulnerability assessment"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Unvalidated scanner output can create false confidence or waste remediation effort.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
1777
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During an e-commerce application review (ECOM-WEB-M05-1777), which risk is most directly associated with "vulnerability assessment"?

View answer choices
  1. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Unvalidated scanner output can create false confidence or waste remediation effort.
  4. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
Practice
1778
Module 5 · Advanced Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a manufacturing and OT security review (MFG-OT-M05-1778), which risk is most directly associated with "vulnerability assessment"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  3. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  4. Unvalidated scanner output can create false confidence or waste remediation effort.
Practice
1779
Module 5 · Advanced Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a mobile-services penetration test (MOB-TEST-M05-1779), which risk is most directly associated with "vulnerability assessment"?

View answer choices
  1. Unvalidated scanner output can create false confidence or waste remediation effort.
  2. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
1780
Module 5 · Advanced Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M05-1780), which risk is most directly associated with "vulnerability assessment"?

View answer choices
  1. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  2. Unvalidated scanner output can create false confidence or waste remediation effort.
  3. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
1781
Module 5 · Foundation Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During an authorized retail-company assessment (RET-LAB-M05-1781), which action most directly controls the risk related to "vulnerability assessment"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Combine authenticated scanning, manual validation, asset criticality, and retesting.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
1782
Module 5 · Foundation Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a hospital incident-response exercise (HLT-SOC-M05-1782), which action most directly controls the risk related to "vulnerability assessment"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  4. Combine authenticated scanning, manual validation, asset criticality, and retesting.
Practice
1783
Module 5 · Foundation Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a university cyber-range engagement (EDU-RANGE-M05-1783), which action most directly controls the risk related to "vulnerability assessment"?

View answer choices
  1. Combine authenticated scanning, manual validation, asset criticality, and retesting.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  4. Define permitted techniques and rates in the rules of engagement.
Practice
1784
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a financial-services purple-team test (FIN-PT-M05-1784), which action most directly controls the risk related to "vulnerability assessment"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Combine authenticated scanning, manual validation, asset criticality, and retesting.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Use appropriate registration privacy and monitor unauthorized domain changes.
Practice
1785
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a cloud startup security audit (CLD-AUDIT-M05-1785), which action most directly controls the risk related to "vulnerability assessment"?

View answer choices
  1. Combine authenticated scanning, manual validation, asset criticality, and retesting.
  2. Use appropriate registration privacy and monitor unauthorized domain changes.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
1786
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a government risk-validation project (GOV-RISK-M05-1786), which action most directly controls the risk related to "vulnerability assessment"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  4. Combine authenticated scanning, manual validation, asset criticality, and retesting.
Practice
1787
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During an e-commerce application review (ECOM-WEB-M05-1787), which action most directly controls the risk related to "vulnerability assessment"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  3. Combine authenticated scanning, manual validation, asset criticality, and retesting.
  4. Define permitted techniques and rates in the rules of engagement.
Practice
1788
Module 5 · Advanced Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a manufacturing and OT security review (MFG-OT-M05-1788), which action most directly controls the risk related to "vulnerability assessment"?

View answer choices
  1. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  2. Combine authenticated scanning, manual validation, asset criticality, and retesting.
  3. Define permitted techniques and rates in the rules of engagement.
  4. Use appropriate registration privacy and monitor unauthorized domain changes.
Practice
1789
Module 5 · Advanced Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a mobile-services penetration test (MOB-TEST-M05-1789), which action most directly controls the risk related to "vulnerability assessment"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Define permitted techniques and rates in the rules of engagement.
  3. Combine authenticated scanning, manual validation, asset criticality, and retesting.
  4. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
Practice
1790
Module 5 · Advanced Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M05-1790), which action most directly controls the risk related to "vulnerability assessment"?

View answer choices
  1. Use appropriate registration privacy and monitor unauthorized domain changes.
  2. Restrict transfers, split sensitive namespaces, and monitor DNS changes.
  3. Combine authenticated scanning, manual validation, asset criticality, and retesting.
  4. Define permitted techniques and rates in the rules of engagement.
Practice
1791
Module 5 · Foundation Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During an authorized retail-company assessment (RET-LAB-M05-1791), which evidence best supports an assessment of "vulnerability assessment"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Registrar records showing nameservers, dates, status codes, and registration contacts.
  4. A finding with affected version, evidence, severity rationale, and remediation status.
Practice
1792
Module 5 · Foundation Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a hospital incident-response exercise (HLT-SOC-M05-1792), which evidence best supports an assessment of "vulnerability assessment"?

View answer choices
  1. A finding with affected version, evidence, severity rationale, and remediation status.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Registrar records showing nameservers, dates, status codes, and registration contacts.
  4. Authoritative DNS responses and a validated map of relevant record types.
Practice
1793
Module 5 · Foundation Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a university cyber-range engagement (EDU-RANGE-M05-1793), which evidence best supports an assessment of "vulnerability assessment"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Timestamped probe logs matched to the approved source and scope.
  3. A finding with affected version, evidence, severity rationale, and remediation status.
  4. Registrar records showing nameservers, dates, status codes, and registration contacts.
Practice
1794
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a financial-services purple-team test (FIN-PT-M05-1794), which evidence best supports an assessment of "vulnerability assessment"?

View answer choices
  1. Registrar records showing nameservers, dates, status codes, and registration contacts.
  2. Authoritative DNS responses and a validated map of relevant record types.
  3. A finding with affected version, evidence, severity rationale, and remediation status.
  4. Timestamped probe logs matched to the approved source and scope.
Practice
1795
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a cloud startup security audit (CLD-AUDIT-M05-1795), which evidence best supports an assessment of "vulnerability assessment"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Registrar records showing nameservers, dates, status codes, and registration contacts.
  4. A finding with affected version, evidence, severity rationale, and remediation status.
Practice
1796
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a government risk-validation project (GOV-RISK-M05-1796), which evidence best supports an assessment of "vulnerability assessment"?

View answer choices
  1. Registrar records showing nameservers, dates, status codes, and registration contacts.
  2. Timestamped probe logs matched to the approved source and scope.
  3. A finding with affected version, evidence, severity rationale, and remediation status.
  4. Authoritative DNS responses and a validated map of relevant record types.
Practice
1797
Module 5 · Applied Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During an e-commerce application review (ECOM-WEB-M05-1797), which evidence best supports an assessment of "vulnerability assessment"?

View answer choices
  1. Timestamped probe logs matched to the approved source and scope.
  2. A finding with affected version, evidence, severity rationale, and remediation status.
  3. Authoritative DNS responses and a validated map of relevant record types.
  4. Registrar records showing nameservers, dates, status codes, and registration contacts.
Practice
1798
Module 5 · Advanced Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a manufacturing and OT security review (MFG-OT-M05-1798), which evidence best supports an assessment of "vulnerability assessment"?

View answer choices
  1. Registrar records showing nameservers, dates, status codes, and registration contacts.
  2. Authoritative DNS responses and a validated map of relevant record types.
  3. A finding with affected version, evidence, severity rationale, and remediation status.
  4. Timestamped probe logs matched to the approved source and scope.
Practice
1799
Module 5 · Advanced Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a mobile-services penetration test (MOB-TEST-M05-1799), which evidence best supports an assessment of "vulnerability assessment"?

View answer choices
  1. Authoritative DNS responses and a validated map of relevant record types.
  2. Registrar records showing nameservers, dates, status codes, and registration contacts.
  3. Timestamped probe logs matched to the approved source and scope.
  4. A finding with affected version, evidence, severity rationale, and remediation status.
Practice
1800
Module 5 · Advanced Domain 2 · Analysis / Assessment vulnerability assessment Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M05-1800), which evidence best supports an assessment of "vulnerability assessment"?

View answer choices
  1. Registrar records showing nameservers, dates, status codes, and registration contacts.
  2. Timestamped probe logs matched to the approved source and scope.
  3. Authoritative DNS responses and a validated map of relevant record types.
  4. A finding with affected version, evidence, severity rationale, and remediation status.
Practice