CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 3,101–3,150 of 5,000 matching questions

50 per page
3101
Module 9 · Foundation Domain 3 · Security phishing-resistant authentication Unanswered

During an authorized retail-company assessment (RET-LAB-M09-3101), which action most directly controls the risk related to "phishing-resistant authentication"?

View answer choices
  1. Use origin-bound cryptographic authenticators and train users to report suspicious prompts.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3102
Module 9 · Foundation Domain 3 · Security phishing-resistant authentication Unanswered

During a hospital incident-response exercise (HLT-SOC-M09-3102), which action most directly controls the risk related to "phishing-resistant authentication"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Use origin-bound cryptographic authenticators and train users to report suspicious prompts.
Practice
3103
Module 9 · Foundation Domain 3 · Security phishing-resistant authentication Unanswered

During a university cyber-range engagement (EDU-RANGE-M09-3103), which action most directly controls the risk related to "phishing-resistant authentication"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Use origin-bound cryptographic authenticators and train users to report suspicious prompts.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3104
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During a financial-services purple-team test (FIN-PT-M09-3104), which action most directly controls the risk related to "phishing-resistant authentication"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Use origin-bound cryptographic authenticators and train users to report suspicious prompts.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3105
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During a cloud startup security audit (CLD-AUDIT-M09-3105), which action most directly controls the risk related to "phishing-resistant authentication"?

View answer choices
  1. Use origin-bound cryptographic authenticators and train users to report suspicious prompts.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3106
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During a government risk-validation project (GOV-RISK-M09-3106), which action most directly controls the risk related to "phishing-resistant authentication"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Use origin-bound cryptographic authenticators and train users to report suspicious prompts.
Practice
3107
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During an e-commerce application review (ECOM-WEB-M09-3107), which action most directly controls the risk related to "phishing-resistant authentication"?

View answer choices
  1. Use origin-bound cryptographic authenticators and train users to report suspicious prompts.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3108
Module 9 · Advanced Domain 3 · Security phishing-resistant authentication Unanswered

During a manufacturing and OT security review (MFG-OT-M09-3108), which action most directly controls the risk related to "phishing-resistant authentication"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Use origin-bound cryptographic authenticators and train users to report suspicious prompts.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3109
Module 9 · Advanced Domain 3 · Security phishing-resistant authentication Unanswered

During a mobile-services penetration test (MOB-TEST-M09-3109), which action most directly controls the risk related to "phishing-resistant authentication"?

View answer choices
  1. Use origin-bound cryptographic authenticators and train users to report suspicious prompts.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3110
Module 9 · Advanced Domain 3 · Security phishing-resistant authentication Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M09-3110), which action most directly controls the risk related to "phishing-resistant authentication"?

View answer choices
  1. Use origin-bound cryptographic authenticators and train users to report suspicious prompts.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3111
Module 9 · Foundation Domain 3 · Security phishing-resistant authentication Unanswered

During an authorized retail-company assessment (RET-LAB-M09-3111), which evidence best supports an assessment of "phishing-resistant authentication"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. Authentication telemetry proving an origin-bound hardware or platform credential was used.
Practice
3112
Module 9 · Foundation Domain 3 · Security phishing-resistant authentication Unanswered

During a hospital incident-response exercise (HLT-SOC-M09-3112), which evidence best supports an assessment of "phishing-resistant authentication"?

View answer choices
  1. Authentication telemetry proving an origin-bound hardware or platform credential was used.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3113
Module 9 · Foundation Domain 3 · Security phishing-resistant authentication Unanswered

During a university cyber-range engagement (EDU-RANGE-M09-3113), which evidence best supports an assessment of "phishing-resistant authentication"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. Authentication telemetry proving an origin-bound hardware or platform credential was used.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3114
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During a financial-services purple-team test (FIN-PT-M09-3114), which evidence best supports an assessment of "phishing-resistant authentication"?

View answer choices
  1. Authentication telemetry proving an origin-bound hardware or platform credential was used.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3115
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During a cloud startup security audit (CLD-AUDIT-M09-3115), which evidence best supports an assessment of "phishing-resistant authentication"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. Authentication telemetry proving an origin-bound hardware or platform credential was used.
Practice
3116
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During a government risk-validation project (GOV-RISK-M09-3116), which evidence best supports an assessment of "phishing-resistant authentication"?

View answer choices
  1. Authentication telemetry proving an origin-bound hardware or platform credential was used.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3117
Module 9 · Applied Domain 3 · Security phishing-resistant authentication Unanswered

During an e-commerce application review (ECOM-WEB-M09-3117), which evidence best supports an assessment of "phishing-resistant authentication"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. Authentication telemetry proving an origin-bound hardware or platform credential was used.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3118
Module 9 · Advanced Domain 3 · Security phishing-resistant authentication Unanswered

During a manufacturing and OT security review (MFG-OT-M09-3118), which evidence best supports an assessment of "phishing-resistant authentication"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. Authentication telemetry proving an origin-bound hardware or platform credential was used.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3119
Module 9 · Advanced Domain 3 · Security phishing-resistant authentication Unanswered

During a mobile-services penetration test (MOB-TEST-M09-3119), which evidence best supports an assessment of "phishing-resistant authentication"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. Authentication telemetry proving an origin-bound hardware or platform credential was used.
Practice
3120
Module 9 · Advanced Domain 3 · Security phishing-resistant authentication Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M09-3120), which evidence best supports an assessment of "phishing-resistant authentication"?

View answer choices
  1. Authentication telemetry proving an origin-bound hardware or platform credential was used.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3121
Module 10 · Foundation Domain 1 · Background denial-of-service attack Unanswered

During an authorized retail-company assessment (RET-LAB-M10-3121), which statement most accurately defines "denial-of-service attack"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. An attack intended to exhaust resources or otherwise make a service unavailable.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
3122
Module 10 · Foundation Domain 1 · Background denial-of-service attack Unanswered

During a hospital incident-response exercise (HLT-SOC-M10-3122), which statement most accurately defines "denial-of-service attack"?

View answer choices
  1. An attack intended to exhaust resources or otherwise make a service unavailable.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
3123
Module 10 · Foundation Domain 1 · Background denial-of-service attack Unanswered

During a university cyber-range engagement (EDU-RANGE-M10-3123), which statement most accurately defines "denial-of-service attack"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. An attack intended to exhaust resources or otherwise make a service unavailable.
Practice
3124
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During a financial-services purple-team test (FIN-PT-M10-3124), which statement most accurately defines "denial-of-service attack"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. An attack intended to exhaust resources or otherwise make a service unavailable.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
3125
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During a cloud startup security audit (CLD-AUDIT-M10-3125), which statement most accurately defines "denial-of-service attack"?

View answer choices
  1. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  2. An attack intended to exhaust resources or otherwise make a service unavailable.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
3126
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During a government risk-validation project (GOV-RISK-M10-3126), which statement most accurately defines "denial-of-service attack"?

View answer choices
  1. An attack intended to exhaust resources or otherwise make a service unavailable.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
3127
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During an e-commerce application review (ECOM-WEB-M10-3127), which statement most accurately defines "denial-of-service attack"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. An attack intended to exhaust resources or otherwise make a service unavailable.
Practice
3128
Module 10 · Advanced Domain 1 · Background denial-of-service attack Unanswered

During a manufacturing and OT security review (MFG-OT-M10-3128), which statement most accurately defines "denial-of-service attack"?

View answer choices
  1. An attack intended to exhaust resources or otherwise make a service unavailable.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
3129
Module 10 · Advanced Domain 1 · Background denial-of-service attack Unanswered

During a mobile-services penetration test (MOB-TEST-M10-3129), which statement most accurately defines "denial-of-service attack"?

View answer choices
  1. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  2. An attack intended to exhaust resources or otherwise make a service unavailable.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
3130
Module 10 · Advanced Domain 1 · Background denial-of-service attack Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M10-3130), which statement most accurately defines "denial-of-service attack"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. An attack intended to exhaust resources or otherwise make a service unavailable.
Practice
3131
Module 10 · Foundation Domain 1 · Background denial-of-service attack Unanswered

During an authorized retail-company assessment (RET-LAB-M10-3131), which risk is most directly associated with "denial-of-service attack"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. A control focused on only one objective can leave the other security objectives exposed.
  3. Resource exhaustion can prevent legitimate users from reaching critical services.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
3132
Module 10 · Foundation Domain 1 · Background denial-of-service attack Unanswered

During a hospital incident-response exercise (HLT-SOC-M10-3132), which risk is most directly associated with "denial-of-service attack"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Resource exhaustion can prevent legitimate users from reaching critical services.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
3133
Module 10 · Foundation Domain 1 · Background denial-of-service attack Unanswered

During a university cyber-range engagement (EDU-RANGE-M10-3133), which risk is most directly associated with "denial-of-service attack"?

View answer choices
  1. Resource exhaustion can prevent legitimate users from reaching critical services.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
3134
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During a financial-services purple-team test (FIN-PT-M10-3134), which risk is most directly associated with "denial-of-service attack"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. Resource exhaustion can prevent legitimate users from reaching critical services.
Practice
3135
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During a cloud startup security audit (CLD-AUDIT-M10-3135), which risk is most directly associated with "denial-of-service attack"?

View answer choices
  1. Resource exhaustion can prevent legitimate users from reaching critical services.
  2. A control focused on only one objective can leave the other security objectives exposed.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
3136
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During a government risk-validation project (GOV-RISK-M10-3136), which risk is most directly associated with "denial-of-service attack"?

View answer choices
  1. Unmapped detections can leave important adversary techniques without coverage.
  2. Resource exhaustion can prevent legitimate users from reaching critical services.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
3137
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During an e-commerce application review (ECOM-WEB-M10-3137), which risk is most directly associated with "denial-of-service attack"?

View answer choices
  1. Resource exhaustion can prevent legitimate users from reaching critical services.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
3138
Module 10 · Advanced Domain 1 · Background denial-of-service attack Unanswered

During a manufacturing and OT security review (MFG-OT-M10-3138), which risk is most directly associated with "denial-of-service attack"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Resource exhaustion can prevent legitimate users from reaching critical services.
Practice
3139
Module 10 · Advanced Domain 1 · Background denial-of-service attack Unanswered

During a mobile-services penetration test (MOB-TEST-M10-3139), which risk is most directly associated with "denial-of-service attack"?

View answer choices
  1. Resource exhaustion can prevent legitimate users from reaching critical services.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
3140
Module 10 · Advanced Domain 1 · Background denial-of-service attack Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M10-3140), which risk is most directly associated with "denial-of-service attack"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Resource exhaustion can prevent legitimate users from reaching critical services.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
3141
Module 10 · Foundation Domain 1 · Background denial-of-service attack Unanswered

During an authorized retail-company assessment (RET-LAB-M10-3141), which action most directly controls the risk related to "denial-of-service attack"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Apply rate controls, resilient architecture, filtering, and upstream mitigation.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
3142
Module 10 · Foundation Domain 1 · Background denial-of-service attack Unanswered

During a hospital incident-response exercise (HLT-SOC-M10-3142), which action most directly controls the risk related to "denial-of-service attack"?

View answer choices
  1. Apply rate controls, resilient architecture, filtering, and upstream mitigation.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
3143
Module 10 · Foundation Domain 1 · Background denial-of-service attack Unanswered

During a university cyber-range engagement (EDU-RANGE-M10-3143), which action most directly controls the risk related to "denial-of-service attack"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Apply rate controls, resilient architecture, filtering, and upstream mitigation.
Practice
3144
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During a financial-services purple-team test (FIN-PT-M10-3144), which action most directly controls the risk related to "denial-of-service attack"?

View answer choices
  1. Apply rate controls, resilient architecture, filtering, and upstream mitigation.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
3145
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During a cloud startup security audit (CLD-AUDIT-M10-3145), which action most directly controls the risk related to "denial-of-service attack"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Apply rate controls, resilient architecture, filtering, and upstream mitigation.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
3146
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During a government risk-validation project (GOV-RISK-M10-3146), which action most directly controls the risk related to "denial-of-service attack"?

View answer choices
  1. Apply rate controls, resilient architecture, filtering, and upstream mitigation.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
3147
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During an e-commerce application review (ECOM-WEB-M10-3147), which action most directly controls the risk related to "denial-of-service attack"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Apply rate controls, resilient architecture, filtering, and upstream mitigation.
Practice
3148
Module 10 · Advanced Domain 1 · Background denial-of-service attack Unanswered

During a manufacturing and OT security review (MFG-OT-M10-3148), which action most directly controls the risk related to "denial-of-service attack"?

View answer choices
  1. Apply rate controls, resilient architecture, filtering, and upstream mitigation.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
3149
Module 10 · Advanced Domain 1 · Background denial-of-service attack Unanswered

During a mobile-services penetration test (MOB-TEST-M10-3149), which action most directly controls the risk related to "denial-of-service attack"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Apply rate controls, resilient architecture, filtering, and upstream mitigation.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
3150
Module 10 · Advanced Domain 1 · Background denial-of-service attack Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M10-3150), which action most directly controls the risk related to "denial-of-service attack"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Apply rate controls, resilient architecture, filtering, and upstream mitigation.
Practice