CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 3,051–3,100 of 5,000 matching questions

50 per page
3051
Module 8 · Foundation Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During an authorized retail-company assessment (RET-LAB-M08-3051), which risk is most directly associated with "tcpdump"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Broad unattended captures can consume storage and collect unnecessary sensitive data.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3052
Module 8 · Foundation Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-3052), which risk is most directly associated with "tcpdump"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Broad unattended captures can consume storage and collect unnecessary sensitive data.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Automated modules can query third parties or collect data outside scope.
Practice
3053
Module 8 · Foundation Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-3053), which risk is most directly associated with "tcpdump"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Broad unattended captures can consume storage and collect unnecessary sensitive data.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3054
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a financial-services purple-team test (FIN-PT-M08-3054), which risk is most directly associated with "tcpdump"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Broad unattended captures can consume storage and collect unnecessary sensitive data.
Practice
3055
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-3055), which risk is most directly associated with "tcpdump"?

View answer choices
  1. Broad unattended captures can consume storage and collect unnecessary sensitive data.
  2. Automated modules can query third parties or collect data outside scope.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3056
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a government risk-validation project (GOV-RISK-M08-3056), which risk is most directly associated with "tcpdump"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Broad unattended captures can consume storage and collect unnecessary sensitive data.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Automated modules can query third parties or collect data outside scope.
Practice
3057
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During an e-commerce application review (ECOM-WEB-M08-3057), which risk is most directly associated with "tcpdump"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Broad unattended captures can consume storage and collect unnecessary sensitive data.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3058
Module 8 · Advanced Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a manufacturing and OT security review (MFG-OT-M08-3058), which risk is most directly associated with "tcpdump"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Automated modules can query third parties or collect data outside scope.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Broad unattended captures can consume storage and collect unnecessary sensitive data.
Practice
3059
Module 8 · Advanced Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a mobile-services penetration test (MOB-TEST-M08-3059), which risk is most directly associated with "tcpdump"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Broad unattended captures can consume storage and collect unnecessary sensitive data.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3060
Module 8 · Advanced Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-3060), which risk is most directly associated with "tcpdump"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Broad unattended captures can consume storage and collect unnecessary sensitive data.
  4. Automated modules can query third parties or collect data outside scope.
Practice
3061
Module 8 · Foundation Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During an authorized retail-company assessment (RET-LAB-M08-3061), which action most directly controls the risk related to "tcpdump"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Use precise capture filters, rotation, permissions, and short collection windows.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3062
Module 8 · Foundation Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-3062), which action most directly controls the risk related to "tcpdump"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Use precise capture filters, rotation, permissions, and short collection windows.
Practice
3063
Module 8 · Foundation Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-3063), which action most directly controls the risk related to "tcpdump"?

View answer choices
  1. Use precise capture filters, rotation, permissions, and short collection windows.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3064
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a financial-services purple-team test (FIN-PT-M08-3064), which action most directly controls the risk related to "tcpdump"?

View answer choices
  1. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  2. Use precise capture filters, rotation, permissions, and short collection windows.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3065
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-3065), which action most directly controls the risk related to "tcpdump"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Use precise capture filters, rotation, permissions, and short collection windows.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3066
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a government risk-validation project (GOV-RISK-M08-3066), which action most directly controls the risk related to "tcpdump"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Use precise capture filters, rotation, permissions, and short collection windows.
Practice
3067
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During an e-commerce application review (ECOM-WEB-M08-3067), which action most directly controls the risk related to "tcpdump"?

View answer choices
  1. Use precise capture filters, rotation, permissions, and short collection windows.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3068
Module 8 · Advanced Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a manufacturing and OT security review (MFG-OT-M08-3068), which action most directly controls the risk related to "tcpdump"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Use precise capture filters, rotation, permissions, and short collection windows.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3069
Module 8 · Advanced Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a mobile-services penetration test (MOB-TEST-M08-3069), which action most directly controls the risk related to "tcpdump"?

View answer choices
  1. Use precise capture filters, rotation, permissions, and short collection windows.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3070
Module 8 · Advanced Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-3070), which action most directly controls the risk related to "tcpdump"?

View answer choices
  1. Use precise capture filters, rotation, permissions, and short collection windows.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3071
Module 8 · Foundation Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During an authorized retail-company assessment (RET-LAB-M08-3071), which evidence best supports an assessment of "tcpdump"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A capture command and pcap showing only the authorized traffic subset.
Practice
3072
Module 8 · Foundation Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-3072), which evidence best supports an assessment of "tcpdump"?

View answer choices
  1. A capture command and pcap showing only the authorized traffic subset.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A relationship graph retaining sources and transformation history.
Practice
3073
Module 8 · Foundation Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-3073), which evidence best supports an assessment of "tcpdump"?

View answer choices
  1. Search results validated against the organization’s current external inventory.
  2. A capture command and pcap showing only the authorized traffic subset.
  3. A relationship graph retaining sources and transformation history.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
3074
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a financial-services purple-team test (FIN-PT-M08-3074), which evidence best supports an assessment of "tcpdump"?

View answer choices
  1. A capture command and pcap showing only the authorized traffic subset.
  2. A relationship graph retaining sources and transformation history.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Search results validated against the organization’s current external inventory.
Practice
3075
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-3075), which evidence best supports an assessment of "tcpdump"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. Search results validated against the organization’s current external inventory.
  3. A relationship graph retaining sources and transformation history.
  4. A capture command and pcap showing only the authorized traffic subset.
Practice
3076
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a government risk-validation project (GOV-RISK-M08-3076), which evidence best supports an assessment of "tcpdump"?

View answer choices
  1. A capture command and pcap showing only the authorized traffic subset.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. Search results validated against the organization’s current external inventory.
  4. A relationship graph retaining sources and transformation history.
Practice
3077
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During an e-commerce application review (ECOM-WEB-M08-3077), which evidence best supports an assessment of "tcpdump"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. A capture command and pcap showing only the authorized traffic subset.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
3078
Module 8 · Advanced Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a manufacturing and OT security review (MFG-OT-M08-3078), which evidence best supports an assessment of "tcpdump"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. A relationship graph retaining sources and transformation history.
  3. A capture command and pcap showing only the authorized traffic subset.
  4. Search results validated against the organization’s current external inventory.
Practice
3079
Module 8 · Advanced Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a mobile-services penetration test (MOB-TEST-M08-3079), which evidence best supports an assessment of "tcpdump"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A capture command and pcap showing only the authorized traffic subset.
Practice
3080
Module 8 · Advanced Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-3080), which evidence best supports an assessment of "tcpdump"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. Search results validated against the organization’s current external inventory.
  3. A capture command and pcap showing only the authorized traffic subset.
  4. A relationship graph retaining sources and transformation history.
Practice
3081
Module 9 · Foundation Domain 3 · Security phishing-resistant authentication Unanswered

During an authorized retail-company assessment (RET-LAB-M09-3081), which statement most accurately defines "phishing-resistant authentication"?

View answer choices
  1. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  2. Authentication designed to resist credential replay and fraudulent verifier sites.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3082
Module 9 · Foundation Domain 3 · Security phishing-resistant authentication Unanswered

During a hospital incident-response exercise (HLT-SOC-M09-3082), which statement most accurately defines "phishing-resistant authentication"?

View answer choices
  1. Authentication designed to resist credential replay and fraudulent verifier sites.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3083
Module 9 · Foundation Domain 3 · Security phishing-resistant authentication Unanswered

During a university cyber-range engagement (EDU-RANGE-M09-3083), which statement most accurately defines "phishing-resistant authentication"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Authentication designed to resist credential replay and fraudulent verifier sites.
Practice
3084
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During a financial-services purple-team test (FIN-PT-M09-3084), which statement most accurately defines "phishing-resistant authentication"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Authentication designed to resist credential replay and fraudulent verifier sites.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3085
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During a cloud startup security audit (CLD-AUDIT-M09-3085), which statement most accurately defines "phishing-resistant authentication"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Authentication designed to resist credential replay and fraudulent verifier sites.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3086
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During a government risk-validation project (GOV-RISK-M09-3086), which statement most accurately defines "phishing-resistant authentication"?

View answer choices
  1. Authentication designed to resist credential replay and fraudulent verifier sites.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3087
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During an e-commerce application review (ECOM-WEB-M09-3087), which statement most accurately defines "phishing-resistant authentication"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Authentication designed to resist credential replay and fraudulent verifier sites.
Practice
3088
Module 9 · Advanced Domain 3 · Security phishing-resistant authentication Unanswered

During a manufacturing and OT security review (MFG-OT-M09-3088), which statement most accurately defines "phishing-resistant authentication"?

View answer choices
  1. Authentication designed to resist credential replay and fraudulent verifier sites.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3089
Module 9 · Advanced Domain 3 · Security phishing-resistant authentication Unanswered

During a mobile-services penetration test (MOB-TEST-M09-3089), which statement most accurately defines "phishing-resistant authentication"?

View answer choices
  1. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  2. Authentication designed to resist credential replay and fraudulent verifier sites.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3090
Module 9 · Advanced Domain 3 · Security phishing-resistant authentication Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M09-3090), which statement most accurately defines "phishing-resistant authentication"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Authentication designed to resist credential replay and fraudulent verifier sites.
Practice
3091
Module 9 · Foundation Domain 3 · Security phishing-resistant authentication Unanswered

During an authorized retail-company assessment (RET-LAB-M09-3091), which risk is most directly associated with "phishing-resistant authentication"?

View answer choices
  1. Traditional passwords and one-time codes can be captured through convincing phishing proxies.
  2. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3092
Module 9 · Foundation Domain 3 · Security phishing-resistant authentication Unanswered

During a hospital incident-response exercise (HLT-SOC-M09-3092), which risk is most directly associated with "phishing-resistant authentication"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Traditional passwords and one-time codes can be captured through convincing phishing proxies.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3093
Module 9 · Foundation Domain 3 · Security phishing-resistant authentication Unanswered

During a university cyber-range engagement (EDU-RANGE-M09-3093), which risk is most directly associated with "phishing-resistant authentication"?

View answer choices
  1. Traditional passwords and one-time codes can be captured through convincing phishing proxies.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3094
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During a financial-services purple-team test (FIN-PT-M09-3094), which risk is most directly associated with "phishing-resistant authentication"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Traditional passwords and one-time codes can be captured through convincing phishing proxies.
Practice
3095
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During a cloud startup security audit (CLD-AUDIT-M09-3095), which risk is most directly associated with "phishing-resistant authentication"?

View answer choices
  1. Traditional passwords and one-time codes can be captured through convincing phishing proxies.
  2. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3096
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During a government risk-validation project (GOV-RISK-M09-3096), which risk is most directly associated with "phishing-resistant authentication"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Traditional passwords and one-time codes can be captured through convincing phishing proxies.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3097
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During an e-commerce application review (ECOM-WEB-M09-3097), which risk is most directly associated with "phishing-resistant authentication"?

View answer choices
  1. Traditional passwords and one-time codes can be captured through convincing phishing proxies.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3098
Module 9 · Advanced Domain 3 · Security phishing-resistant authentication Unanswered

During a manufacturing and OT security review (MFG-OT-M09-3098), which risk is most directly associated with "phishing-resistant authentication"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Traditional passwords and one-time codes can be captured through convincing phishing proxies.
Practice
3099
Module 9 · Advanced Domain 3 · Security phishing-resistant authentication Unanswered

During a mobile-services penetration test (MOB-TEST-M09-3099), which risk is most directly associated with "phishing-resistant authentication"?

View answer choices
  1. Traditional passwords and one-time codes can be captured through convincing phishing proxies.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3100
Module 9 · Advanced Domain 3 · Security phishing-resistant authentication Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M09-3100), which risk is most directly associated with "phishing-resistant authentication"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Traditional passwords and one-time codes can be captured through convincing phishing proxies.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice