CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 2,951–3,000 of 5,000 matching questions

50 per page
2951
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Bettercap Unanswered

During an authorized retail-company assessment (RET-LAB-M08-2951), which evidence best supports an assessment of "Bettercap"?

View answer choices
  1. Tool events correlated with packet capture and target-side security alerts.
  2. A relationship graph retaining sources and transformation history.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Search results validated against the organization’s current external inventory.
Practice
2952
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Bettercap Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-2952), which evidence best supports an assessment of "Bettercap"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Tool events correlated with packet capture and target-side security alerts.
  3. Search results validated against the organization’s current external inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
2953
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Bettercap Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-2953), which evidence best supports an assessment of "Bettercap"?

View answer choices
  1. Tool events correlated with packet capture and target-side security alerts.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A relationship graph retaining sources and transformation history.
Practice
2954
Module 8 · Applied Domain 4 · Tools / Systems / Programs Bettercap Unanswered

During a financial-services purple-team test (FIN-PT-M08-2954), which evidence best supports an assessment of "Bettercap"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. Search results validated against the organization’s current external inventory.
  4. Tool events correlated with packet capture and target-side security alerts.
Practice
2955
Module 8 · Applied Domain 4 · Tools / Systems / Programs Bettercap Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-2955), which evidence best supports an assessment of "Bettercap"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. A relationship graph retaining sources and transformation history.
  3. Tool events correlated with packet capture and target-side security alerts.
  4. Search results validated against the organization’s current external inventory.
Practice
2956
Module 8 · Applied Domain 4 · Tools / Systems / Programs Bettercap Unanswered

During a government risk-validation project (GOV-RISK-M08-2956), which evidence best supports an assessment of "Bettercap"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Tool events correlated with packet capture and target-side security alerts.
  3. Search results validated against the organization’s current external inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
2957
Module 8 · Applied Domain 4 · Tools / Systems / Programs Bettercap Unanswered

During an e-commerce application review (ECOM-WEB-M08-2957), which evidence best supports an assessment of "Bettercap"?

View answer choices
  1. Tool events correlated with packet capture and target-side security alerts.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. Search results validated against the organization’s current external inventory.
  4. A relationship graph retaining sources and transformation history.
Practice
2958
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Bettercap Unanswered

During a manufacturing and OT security review (MFG-OT-M08-2958), which evidence best supports an assessment of "Bettercap"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. Search results validated against the organization’s current external inventory.
  3. A relationship graph retaining sources and transformation history.
  4. Tool events correlated with packet capture and target-side security alerts.
Practice
2959
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Bettercap Unanswered

During a mobile-services penetration test (MOB-TEST-M08-2959), which evidence best supports an assessment of "Bettercap"?

View answer choices
  1. Tool events correlated with packet capture and target-side security alerts.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. A relationship graph retaining sources and transformation history.
  4. Search results validated against the organization’s current external inventory.
Practice
2960
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Bettercap Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-2960), which evidence best supports an assessment of "Bettercap"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Tool events correlated with packet capture and target-side security alerts.
  3. Search results validated against the organization’s current external inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
2961
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Responder Unanswered

During an authorized retail-company assessment (RET-LAB-M08-2961), which statement most accurately defines "Responder"?

View answer choices
  1. A security-testing tool that listens for name-resolution requests and can capture challenge-response authentication attempts.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
2962
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Responder Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-2962), which statement most accurately defines "Responder"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A security-testing tool that listens for name-resolution requests and can capture challenge-response authentication attempts.
Practice
2963
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Responder Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-2963), which statement most accurately defines "Responder"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A security-testing tool that listens for name-resolution requests and can capture challenge-response authentication attempts.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
2964
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During a financial-services purple-team test (FIN-PT-M08-2964), which statement most accurately defines "Responder"?

View answer choices
  1. A search service that indexes Internet-connected devices and service banners.
  2. A security-testing tool that listens for name-resolution requests and can capture challenge-response authentication attempts.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
2965
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-2965), which statement most accurately defines "Responder"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A security-testing tool that listens for name-resolution requests and can capture challenge-response authentication attempts.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
2966
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During a government risk-validation project (GOV-RISK-M08-2966), which statement most accurately defines "Responder"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A security-testing tool that listens for name-resolution requests and can capture challenge-response authentication attempts.
Practice
2967
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During an e-commerce application review (ECOM-WEB-M08-2967), which statement most accurately defines "Responder"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A security-testing tool that listens for name-resolution requests and can capture challenge-response authentication attempts.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
2968
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Responder Unanswered

During a manufacturing and OT security review (MFG-OT-M08-2968), which statement most accurately defines "Responder"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A security-testing tool that listens for name-resolution requests and can capture challenge-response authentication attempts.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
2969
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Responder Unanswered

During a mobile-services penetration test (MOB-TEST-M08-2969), which statement most accurately defines "Responder"?

View answer choices
  1. A security-testing tool that listens for name-resolution requests and can capture challenge-response authentication attempts.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
2970
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Responder Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-2970), which statement most accurately defines "Responder"?

View answer choices
  1. A security-testing tool that listens for name-resolution requests and can capture challenge-response authentication attempts.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
2971
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Responder Unanswered

During an authorized retail-company assessment (RET-LAB-M08-2971), which risk is most directly associated with "Responder"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Poisoned local name resolution can lead clients to disclose reusable authentication material.
Practice
2972
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Responder Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-2972), which risk is most directly associated with "Responder"?

View answer choices
  1. Poisoned local name resolution can lead clients to disclose reusable authentication material.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
2973
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Responder Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-2973), which risk is most directly associated with "Responder"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Poisoned local name resolution can lead clients to disclose reusable authentication material.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Automated modules can query third parties or collect data outside scope.
Practice
2974
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During a financial-services purple-team test (FIN-PT-M08-2974), which risk is most directly associated with "Responder"?

View answer choices
  1. Poisoned local name resolution can lead clients to disclose reusable authentication material.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Automated modules can query third parties or collect data outside scope.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
2975
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-2975), which risk is most directly associated with "Responder"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Poisoned local name resolution can lead clients to disclose reusable authentication material.
Practice
2976
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During a government risk-validation project (GOV-RISK-M08-2976), which risk is most directly associated with "Responder"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Poisoned local name resolution can lead clients to disclose reusable authentication material.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
2977
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During an e-commerce application review (ECOM-WEB-M08-2977), which risk is most directly associated with "Responder"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Poisoned local name resolution can lead clients to disclose reusable authentication material.
  4. Automated modules can query third parties or collect data outside scope.
Practice
2978
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Responder Unanswered

During a manufacturing and OT security review (MFG-OT-M08-2978), which risk is most directly associated with "Responder"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Poisoned local name resolution can lead clients to disclose reusable authentication material.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
2979
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Responder Unanswered

During a mobile-services penetration test (MOB-TEST-M08-2979), which risk is most directly associated with "Responder"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Poisoned local name resolution can lead clients to disclose reusable authentication material.
Practice
2980
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Responder Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-2980), which risk is most directly associated with "Responder"?

View answer choices
  1. Poisoned local name resolution can lead clients to disclose reusable authentication material.
  2. Automated modules can query third parties or collect data outside scope.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
2981
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Responder Unanswered

During an authorized retail-company assessment (RET-LAB-M08-2981), which action most directly controls the risk related to "Responder"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Disable unsafe fallback protocols, enforce signing, and monitor spoofed responses.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
2982
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Responder Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-2982), which action most directly controls the risk related to "Responder"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Disable unsafe fallback protocols, enforce signing, and monitor spoofed responses.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
2983
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Responder Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-2983), which action most directly controls the risk related to "Responder"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Disable unsafe fallback protocols, enforce signing, and monitor spoofed responses.
Practice
2984
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During a financial-services purple-team test (FIN-PT-M08-2984), which action most directly controls the risk related to "Responder"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Disable unsafe fallback protocols, enforce signing, and monitor spoofed responses.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
2985
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-2985), which action most directly controls the risk related to "Responder"?

View answer choices
  1. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  2. Disable unsafe fallback protocols, enforce signing, and monitor spoofed responses.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
2986
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During a government risk-validation project (GOV-RISK-M08-2986), which action most directly controls the risk related to "Responder"?

View answer choices
  1. Disable unsafe fallback protocols, enforce signing, and monitor spoofed responses.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
2987
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During an e-commerce application review (ECOM-WEB-M08-2987), which action most directly controls the risk related to "Responder"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Disable unsafe fallback protocols, enforce signing, and monitor spoofed responses.
Practice
2988
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Responder Unanswered

During a manufacturing and OT security review (MFG-OT-M08-2988), which action most directly controls the risk related to "Responder"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Disable unsafe fallback protocols, enforce signing, and monitor spoofed responses.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
2989
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Responder Unanswered

During a mobile-services penetration test (MOB-TEST-M08-2989), which action most directly controls the risk related to "Responder"?

View answer choices
  1. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  2. Disable unsafe fallback protocols, enforce signing, and monitor spoofed responses.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
2990
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Responder Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-2990), which action most directly controls the risk related to "Responder"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Disable unsafe fallback protocols, enforce signing, and monitor spoofed responses.
Practice
2991
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Responder Unanswered

During an authorized retail-company assessment (RET-LAB-M08-2991), which evidence best supports an assessment of "Responder"?

View answer choices
  1. Captured resolution requests and authentication events from the authorized lab.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. A relationship graph retaining sources and transformation history.
  4. Search results validated against the organization’s current external inventory.
Practice
2992
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Responder Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-2992), which evidence best supports an assessment of "Responder"?

View answer choices
  1. Search results validated against the organization’s current external inventory.
  2. Captured resolution requests and authentication events from the authorized lab.
  3. A relationship graph retaining sources and transformation history.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
2993
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Responder Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-2993), which evidence best supports an assessment of "Responder"?

View answer choices
  1. Captured resolution requests and authentication events from the authorized lab.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A relationship graph retaining sources and transformation history.
Practice
2994
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During a financial-services purple-team test (FIN-PT-M08-2994), which evidence best supports an assessment of "Responder"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Captured resolution requests and authentication events from the authorized lab.
Practice
2995
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-2995), which evidence best supports an assessment of "Responder"?

View answer choices
  1. Captured resolution requests and authentication events from the authorized lab.
  2. A relationship graph retaining sources and transformation history.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Search results validated against the organization’s current external inventory.
Practice
2996
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During a government risk-validation project (GOV-RISK-M08-2996), which evidence best supports an assessment of "Responder"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Captured resolution requests and authentication events from the authorized lab.
  3. Search results validated against the organization’s current external inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
2997
Module 8 · Applied Domain 4 · Tools / Systems / Programs Responder Unanswered

During an e-commerce application review (ECOM-WEB-M08-2997), which evidence best supports an assessment of "Responder"?

View answer choices
  1. Captured resolution requests and authentication events from the authorized lab.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. Search results validated against the organization’s current external inventory.
  4. A relationship graph retaining sources and transformation history.
Practice
2998
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Responder Unanswered

During a manufacturing and OT security review (MFG-OT-M08-2998), which evidence best supports an assessment of "Responder"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. Search results validated against the organization’s current external inventory.
  4. Captured resolution requests and authentication events from the authorized lab.
Practice
2999
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Responder Unanswered

During a mobile-services penetration test (MOB-TEST-M08-2999), which evidence best supports an assessment of "Responder"?

View answer choices
  1. Captured resolution requests and authentication events from the authorized lab.
  2. A relationship graph retaining sources and transformation history.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Search results validated against the organization’s current external inventory.
Practice
3000
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Responder Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-3000), which evidence best supports an assessment of "Responder"?

View answer choices
  1. Search results validated against the organization’s current external inventory.
  2. Captured resolution requests and authentication events from the authorized lab.
  3. A relationship graph retaining sources and transformation history.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice