CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 2,001–2,050 of 5,000 matching questions

50 per page
2001
Module 6 · Foundation Domain 3 · Security least privilege Unanswered

During an authorized retail-company assessment (RET-LAB-M06-2001), which statement most accurately defines "least privilege"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Granting identities only the permissions required for their current tasks.
Practice
2002
Module 6 · Foundation Domain 3 · Security least privilege Unanswered

During a hospital incident-response exercise (HLT-SOC-M06-2002), which statement most accurately defines "least privilege"?

View answer choices
  1. Granting identities only the permissions required for their current tasks.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
2003
Module 6 · Foundation Domain 3 · Security least privilege Unanswered

During a university cyber-range engagement (EDU-RANGE-M06-2003), which statement most accurately defines "least privilege"?

View answer choices
  1. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  2. Granting identities only the permissions required for their current tasks.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
2004
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During a financial-services purple-team test (FIN-PT-M06-2004), which statement most accurately defines "least privilege"?

View answer choices
  1. Granting identities only the permissions required for their current tasks.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
2005
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During a cloud startup security audit (CLD-AUDIT-M06-2005), which statement most accurately defines "least privilege"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Granting identities only the permissions required for their current tasks.
Practice
2006
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During a government risk-validation project (GOV-RISK-M06-2006), which statement most accurately defines "least privilege"?

View answer choices
  1. Granting identities only the permissions required for their current tasks.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
2007
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During an e-commerce application review (ECOM-WEB-M06-2007), which statement most accurately defines "least privilege"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Granting identities only the permissions required for their current tasks.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
2008
Module 6 · Advanced Domain 3 · Security least privilege Unanswered

During a manufacturing and OT security review (MFG-OT-M06-2008), which statement most accurately defines "least privilege"?

View answer choices
  1. Granting identities only the permissions required for their current tasks.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
2009
Module 6 · Advanced Domain 3 · Security least privilege Unanswered

During a mobile-services penetration test (MOB-TEST-M06-2009), which statement most accurately defines "least privilege"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Granting identities only the permissions required for their current tasks.
Practice
2010
Module 6 · Advanced Domain 3 · Security least privilege Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M06-2010), which statement most accurately defines "least privilege"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Granting identities only the permissions required for their current tasks.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
2011
Module 6 · Foundation Domain 3 · Security least privilege Unanswered

During an authorized retail-company assessment (RET-LAB-M06-2011), which risk is most directly associated with "least privilege"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Excessive privileges increase the impact of stolen credentials and mistakes.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
2012
Module 6 · Foundation Domain 3 · Security least privilege Unanswered

During a hospital incident-response exercise (HLT-SOC-M06-2012), which risk is most directly associated with "least privilege"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Excessive privileges increase the impact of stolen credentials and mistakes.
Practice
2013
Module 6 · Foundation Domain 3 · Security least privilege Unanswered

During a university cyber-range engagement (EDU-RANGE-M06-2013), which risk is most directly associated with "least privilege"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Excessive privileges increase the impact of stolen credentials and mistakes.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
2014
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During a financial-services purple-team test (FIN-PT-M06-2014), which risk is most directly associated with "least privilege"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Excessive privileges increase the impact of stolen credentials and mistakes.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
2015
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During a cloud startup security audit (CLD-AUDIT-M06-2015), which risk is most directly associated with "least privilege"?

View answer choices
  1. Excessive privileges increase the impact of stolen credentials and mistakes.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
2016
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During a government risk-validation project (GOV-RISK-M06-2016), which risk is most directly associated with "least privilege"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Excessive privileges increase the impact of stolen credentials and mistakes.
Practice
2017
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During an e-commerce application review (ECOM-WEB-M06-2017), which risk is most directly associated with "least privilege"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Excessive privileges increase the impact of stolen credentials and mistakes.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
2018
Module 6 · Advanced Domain 3 · Security least privilege Unanswered

During a manufacturing and OT security review (MFG-OT-M06-2018), which risk is most directly associated with "least privilege"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Excessive privileges increase the impact of stolen credentials and mistakes.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
2019
Module 6 · Advanced Domain 3 · Security least privilege Unanswered

During a mobile-services penetration test (MOB-TEST-M06-2019), which risk is most directly associated with "least privilege"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Excessive privileges increase the impact of stolen credentials and mistakes.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
2020
Module 6 · Advanced Domain 3 · Security least privilege Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M06-2020), which risk is most directly associated with "least privilege"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Excessive privileges increase the impact of stolen credentials and mistakes.
Practice
2021
Module 6 · Foundation Domain 3 · Security least privilege Unanswered

During an authorized retail-company assessment (RET-LAB-M06-2021), which action most directly controls the risk related to "least privilege"?

View answer choices
  1. Use role-based access, just-in-time elevation, reviews, and separation of duties.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
2022
Module 6 · Foundation Domain 3 · Security least privilege Unanswered

During a hospital incident-response exercise (HLT-SOC-M06-2022), which action most directly controls the risk related to "least privilege"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Use role-based access, just-in-time elevation, reviews, and separation of duties.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
2023
Module 6 · Foundation Domain 3 · Security least privilege Unanswered

During a university cyber-range engagement (EDU-RANGE-M06-2023), which action most directly controls the risk related to "least privilege"?

View answer choices
  1. Use role-based access, just-in-time elevation, reviews, and separation of duties.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
2024
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During a financial-services purple-team test (FIN-PT-M06-2024), which action most directly controls the risk related to "least privilege"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Use role-based access, just-in-time elevation, reviews, and separation of duties.
Practice
2025
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During a cloud startup security audit (CLD-AUDIT-M06-2025), which action most directly controls the risk related to "least privilege"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Use role-based access, just-in-time elevation, reviews, and separation of duties.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
2026
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During a government risk-validation project (GOV-RISK-M06-2026), which action most directly controls the risk related to "least privilege"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Use role-based access, just-in-time elevation, reviews, and separation of duties.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
2027
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During an e-commerce application review (ECOM-WEB-M06-2027), which action most directly controls the risk related to "least privilege"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Use role-based access, just-in-time elevation, reviews, and separation of duties.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
2028
Module 6 · Advanced Domain 3 · Security least privilege Unanswered

During a manufacturing and OT security review (MFG-OT-M06-2028), which action most directly controls the risk related to "least privilege"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Use role-based access, just-in-time elevation, reviews, and separation of duties.
Practice
2029
Module 6 · Advanced Domain 3 · Security least privilege Unanswered

During a mobile-services penetration test (MOB-TEST-M06-2029), which action most directly controls the risk related to "least privilege"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Use role-based access, just-in-time elevation, reviews, and separation of duties.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
2030
Module 6 · Advanced Domain 3 · Security least privilege Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M06-2030), which action most directly controls the risk related to "least privilege"?

View answer choices
  1. Use role-based access, just-in-time elevation, reviews, and separation of duties.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
2031
Module 6 · Foundation Domain 3 · Security least privilege Unanswered

During an authorized retail-company assessment (RET-LAB-M06-2031), which evidence best supports an assessment of "least privilege"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. Entitlement records showing business justification, approval, use, and expiration.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
2032
Module 6 · Foundation Domain 3 · Security least privilege Unanswered

During a hospital incident-response exercise (HLT-SOC-M06-2032), which evidence best supports an assessment of "least privilege"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. Entitlement records showing business justification, approval, use, and expiration.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
2033
Module 6 · Foundation Domain 3 · Security least privilege Unanswered

During a university cyber-range engagement (EDU-RANGE-M06-2033), which evidence best supports an assessment of "least privilege"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. Entitlement records showing business justification, approval, use, and expiration.
Practice
2034
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During a financial-services purple-team test (FIN-PT-M06-2034), which evidence best supports an assessment of "least privilege"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. Entitlement records showing business justification, approval, use, and expiration.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
2035
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During a cloud startup security audit (CLD-AUDIT-M06-2035), which evidence best supports an assessment of "least privilege"?

View answer choices
  1. A risk register with likelihood, impact, owner, treatment, and review date.
  2. Entitlement records showing business justification, approval, use, and expiration.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
2036
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During a government risk-validation project (GOV-RISK-M06-2036), which evidence best supports an assessment of "least privilege"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. Entitlement records showing business justification, approval, use, and expiration.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
2037
Module 6 · Applied Domain 3 · Security least privilege Unanswered

During an e-commerce application review (ECOM-WEB-M06-2037), which evidence best supports an assessment of "least privilege"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. Entitlement records showing business justification, approval, use, and expiration.
Practice
2038
Module 6 · Advanced Domain 3 · Security least privilege Unanswered

During a manufacturing and OT security review (MFG-OT-M06-2038), which evidence best supports an assessment of "least privilege"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. Entitlement records showing business justification, approval, use, and expiration.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
2039
Module 6 · Advanced Domain 3 · Security least privilege Unanswered

During a mobile-services penetration test (MOB-TEST-M06-2039), which evidence best supports an assessment of "least privilege"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. Entitlement records showing business justification, approval, use, and expiration.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
2040
Module 6 · Advanced Domain 3 · Security least privilege Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M06-2040), which evidence best supports an assessment of "least privilege"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. Entitlement records showing business justification, approval, use, and expiration.
Practice
2041
Module 6 · Foundation Domain 3 · Security multi-factor authentication Unanswered

During an authorized retail-company assessment (RET-LAB-M06-2041), which statement most accurately defines "multi-factor authentication"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Authentication that requires factors from different categories such as knowledge and possession.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
2042
Module 6 · Foundation Domain 3 · Security multi-factor authentication Unanswered

During a hospital incident-response exercise (HLT-SOC-M06-2042), which statement most accurately defines "multi-factor authentication"?

View answer choices
  1. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  2. Authentication that requires factors from different categories such as knowledge and possession.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
2043
Module 6 · Foundation Domain 3 · Security multi-factor authentication Unanswered

During a university cyber-range engagement (EDU-RANGE-M06-2043), which statement most accurately defines "multi-factor authentication"?

View answer choices
  1. Authentication that requires factors from different categories such as knowledge and possession.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
2044
Module 6 · Applied Domain 3 · Security multi-factor authentication Unanswered

During a financial-services purple-team test (FIN-PT-M06-2044), which statement most accurately defines "multi-factor authentication"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Authentication that requires factors from different categories such as knowledge and possession.
Practice
2045
Module 6 · Applied Domain 3 · Security multi-factor authentication Unanswered

During a cloud startup security audit (CLD-AUDIT-M06-2045), which statement most accurately defines "multi-factor authentication"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Authentication that requires factors from different categories such as knowledge and possession.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
2046
Module 6 · Applied Domain 3 · Security multi-factor authentication Unanswered

During a government risk-validation project (GOV-RISK-M06-2046), which statement most accurately defines "multi-factor authentication"?

View answer choices
  1. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  2. Authentication that requires factors from different categories such as knowledge and possession.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
2047
Module 6 · Applied Domain 3 · Security multi-factor authentication Unanswered

During an e-commerce application review (ECOM-WEB-M06-2047), which statement most accurately defines "multi-factor authentication"?

View answer choices
  1. Authentication that requires factors from different categories such as knowledge and possession.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
2048
Module 6 · Advanced Domain 3 · Security multi-factor authentication Unanswered

During a manufacturing and OT security review (MFG-OT-M06-2048), which statement most accurately defines "multi-factor authentication"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Authentication that requires factors from different categories such as knowledge and possession.
Practice
2049
Module 6 · Advanced Domain 3 · Security multi-factor authentication Unanswered

During a mobile-services penetration test (MOB-TEST-M06-2049), which statement most accurately defines "multi-factor authentication"?

View answer choices
  1. Authentication that requires factors from different categories such as knowledge and possession.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
2050
Module 6 · Advanced Domain 3 · Security multi-factor authentication Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M06-2050), which statement most accurately defines "multi-factor authentication"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Authentication that requires factors from different categories such as knowledge and possession.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice