CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 3,151–3,200 of 5,000 matching questions

50 per page
3151
Module 10 · Foundation Domain 1 · Background denial-of-service attack Unanswered

During an authorized retail-company assessment (RET-LAB-M10-3151), which evidence best supports an assessment of "denial-of-service attack"?

View answer choices
  1. Traffic and resource metrics showing the saturation point and attack pattern.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A risk register linking assets to CIA impact ratings.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
3152
Module 10 · Foundation Domain 1 · Background denial-of-service attack Unanswered

During a hospital incident-response exercise (HLT-SOC-M10-3152), which evidence best supports an assessment of "denial-of-service attack"?

View answer choices
  1. A detection matrix showing covered and uncovered ATT&CK techniques.
  2. Traffic and resource metrics showing the saturation point and attack pattern.
  3. A risk register linking assets to CIA impact ratings.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
3153
Module 10 · Foundation Domain 1 · Background denial-of-service attack Unanswered

During a university cyber-range engagement (EDU-RANGE-M10-3153), which evidence best supports an assessment of "denial-of-service attack"?

View answer choices
  1. Traffic and resource metrics showing the saturation point and attack pattern.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. A risk register linking assets to CIA impact ratings.
Practice
3154
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During a financial-services purple-team test (FIN-PT-M10-3154), which evidence best supports an assessment of "denial-of-service attack"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. Traffic and resource metrics showing the saturation point and attack pattern.
Practice
3155
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During a cloud startup security audit (CLD-AUDIT-M10-3155), which evidence best supports an assessment of "denial-of-service attack"?

View answer choices
  1. Traffic and resource metrics showing the saturation point and attack pattern.
  2. A risk register linking assets to CIA impact ratings.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
3156
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During a government risk-validation project (GOV-RISK-M10-3156), which evidence best supports an assessment of "denial-of-service attack"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. Traffic and resource metrics showing the saturation point and attack pattern.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
3157
Module 10 · Applied Domain 1 · Background denial-of-service attack Unanswered

During an e-commerce application review (ECOM-WEB-M10-3157), which evidence best supports an assessment of "denial-of-service attack"?

View answer choices
  1. Traffic and resource metrics showing the saturation point and attack pattern.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A risk register linking assets to CIA impact ratings.
Practice
3158
Module 10 · Advanced Domain 1 · Background denial-of-service attack Unanswered

During a manufacturing and OT security review (MFG-OT-M10-3158), which evidence best supports an assessment of "denial-of-service attack"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. Traffic and resource metrics showing the saturation point and attack pattern.
Practice
3159
Module 10 · Advanced Domain 1 · Background denial-of-service attack Unanswered

During a mobile-services penetration test (MOB-TEST-M10-3159), which evidence best supports an assessment of "denial-of-service attack"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A risk register linking assets to CIA impact ratings.
  3. Traffic and resource metrics showing the saturation point and attack pattern.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
3160
Module 10 · Advanced Domain 1 · Background denial-of-service attack Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M10-3160), which evidence best supports an assessment of "denial-of-service attack"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. Traffic and resource metrics showing the saturation point and attack pattern.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
3161
Module 10 · Foundation Domain 3 · Security DDoS mitigation Unanswered

During an authorized retail-company assessment (RET-LAB-M10-3161), which statement most accurately defines "DDoS mitigation"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Controls that detect and absorb, filter, or reroute malicious traffic intended to exhaust services.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3162
Module 10 · Foundation Domain 3 · Security DDoS mitigation Unanswered

During a hospital incident-response exercise (HLT-SOC-M10-3162), which statement most accurately defines "DDoS mitigation"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Controls that detect and absorb, filter, or reroute malicious traffic intended to exhaust services.
Practice
3163
Module 10 · Foundation Domain 3 · Security DDoS mitigation Unanswered

During a university cyber-range engagement (EDU-RANGE-M10-3163), which statement most accurately defines "DDoS mitigation"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Controls that detect and absorb, filter, or reroute malicious traffic intended to exhaust services.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3164
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During a financial-services purple-team test (FIN-PT-M10-3164), which statement most accurately defines "DDoS mitigation"?

View answer choices
  1. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  2. Controls that detect and absorb, filter, or reroute malicious traffic intended to exhaust services.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3165
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During a cloud startup security audit (CLD-AUDIT-M10-3165), which statement most accurately defines "DDoS mitigation"?

View answer choices
  1. Controls that detect and absorb, filter, or reroute malicious traffic intended to exhaust services.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3166
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During a government risk-validation project (GOV-RISK-M10-3166), which statement most accurately defines "DDoS mitigation"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Controls that detect and absorb, filter, or reroute malicious traffic intended to exhaust services.
Practice
3167
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During an e-commerce application review (ECOM-WEB-M10-3167), which statement most accurately defines "DDoS mitigation"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Controls that detect and absorb, filter, or reroute malicious traffic intended to exhaust services.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3168
Module 10 · Advanced Domain 3 · Security DDoS mitigation Unanswered

During a manufacturing and OT security review (MFG-OT-M10-3168), which statement most accurately defines "DDoS mitigation"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Controls that detect and absorb, filter, or reroute malicious traffic intended to exhaust services.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3169
Module 10 · Advanced Domain 3 · Security DDoS mitigation Unanswered

During a mobile-services penetration test (MOB-TEST-M10-3169), which statement most accurately defines "DDoS mitigation"?

View answer choices
  1. Controls that detect and absorb, filter, or reroute malicious traffic intended to exhaust services.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3170
Module 10 · Advanced Domain 3 · Security DDoS mitigation Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M10-3170), which statement most accurately defines "DDoS mitigation"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Controls that detect and absorb, filter, or reroute malicious traffic intended to exhaust services.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3171
Module 10 · Foundation Domain 3 · Security DDoS mitigation Unanswered

During an authorized retail-company assessment (RET-LAB-M10-3171), which risk is most directly associated with "DDoS mitigation"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Local capacity may saturate before an on-premises device can filter the attack.
Practice
3172
Module 10 · Foundation Domain 3 · Security DDoS mitigation Unanswered

During a hospital incident-response exercise (HLT-SOC-M10-3172), which risk is most directly associated with "DDoS mitigation"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Local capacity may saturate before an on-premises device can filter the attack.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3173
Module 10 · Foundation Domain 3 · Security DDoS mitigation Unanswered

During a university cyber-range engagement (EDU-RANGE-M10-3173), which risk is most directly associated with "DDoS mitigation"?

View answer choices
  1. Controls chosen without risk context may protect low-value assets while critical risks remain.
  2. Local capacity may saturate before an on-premises device can filter the attack.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3174
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During a financial-services purple-team test (FIN-PT-M10-3174), which risk is most directly associated with "DDoS mitigation"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Local capacity may saturate before an on-premises device can filter the attack.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3175
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During a cloud startup security audit (CLD-AUDIT-M10-3175), which risk is most directly associated with "DDoS mitigation"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Local capacity may saturate before an on-premises device can filter the attack.
Practice
3176
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During a government risk-validation project (GOV-RISK-M10-3176), which risk is most directly associated with "DDoS mitigation"?

View answer choices
  1. Local capacity may saturate before an on-premises device can filter the attack.
  2. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3177
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During an e-commerce application review (ECOM-WEB-M10-3177), which risk is most directly associated with "DDoS mitigation"?

View answer choices
  1. Controls chosen without risk context may protect low-value assets while critical risks remain.
  2. Local capacity may saturate before an on-premises device can filter the attack.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3178
Module 10 · Advanced Domain 3 · Security DDoS mitigation Unanswered

During a manufacturing and OT security review (MFG-OT-M10-3178), which risk is most directly associated with "DDoS mitigation"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Local capacity may saturate before an on-premises device can filter the attack.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3179
Module 10 · Advanced Domain 3 · Security DDoS mitigation Unanswered

During a mobile-services penetration test (MOB-TEST-M10-3179), which risk is most directly associated with "DDoS mitigation"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Local capacity may saturate before an on-premises device can filter the attack.
Practice
3180
Module 10 · Advanced Domain 3 · Security DDoS mitigation Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M10-3180), which risk is most directly associated with "DDoS mitigation"?

View answer choices
  1. Local capacity may saturate before an on-premises device can filter the attack.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3181
Module 10 · Foundation Domain 3 · Security DDoS mitigation Unanswered

During an authorized retail-company assessment (RET-LAB-M10-3181), which action most directly controls the risk related to "DDoS mitigation"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Combine resilient design, upstream scrubbing, rate controls, and rehearsed activation.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3182
Module 10 · Foundation Domain 3 · Security DDoS mitigation Unanswered

During a hospital incident-response exercise (HLT-SOC-M10-3182), which action most directly controls the risk related to "DDoS mitigation"?

View answer choices
  1. Combine resilient design, upstream scrubbing, rate controls, and rehearsed activation.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3183
Module 10 · Foundation Domain 3 · Security DDoS mitigation Unanswered

During a university cyber-range engagement (EDU-RANGE-M10-3183), which action most directly controls the risk related to "DDoS mitigation"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Combine resilient design, upstream scrubbing, rate controls, and rehearsed activation.
Practice
3184
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During a financial-services purple-team test (FIN-PT-M10-3184), which action most directly controls the risk related to "DDoS mitigation"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Combine resilient design, upstream scrubbing, rate controls, and rehearsed activation.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3185
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During a cloud startup security audit (CLD-AUDIT-M10-3185), which action most directly controls the risk related to "DDoS mitigation"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Combine resilient design, upstream scrubbing, rate controls, and rehearsed activation.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3186
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During a government risk-validation project (GOV-RISK-M10-3186), which action most directly controls the risk related to "DDoS mitigation"?

View answer choices
  1. Combine resilient design, upstream scrubbing, rate controls, and rehearsed activation.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3187
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During an e-commerce application review (ECOM-WEB-M10-3187), which action most directly controls the risk related to "DDoS mitigation"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Combine resilient design, upstream scrubbing, rate controls, and rehearsed activation.
Practice
3188
Module 10 · Advanced Domain 3 · Security DDoS mitigation Unanswered

During a manufacturing and OT security review (MFG-OT-M10-3188), which action most directly controls the risk related to "DDoS mitigation"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Combine resilient design, upstream scrubbing, rate controls, and rehearsed activation.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3189
Module 10 · Advanced Domain 3 · Security DDoS mitigation Unanswered

During a mobile-services penetration test (MOB-TEST-M10-3189), which action most directly controls the risk related to "DDoS mitigation"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Combine resilient design, upstream scrubbing, rate controls, and rehearsed activation.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3190
Module 10 · Advanced Domain 3 · Security DDoS mitigation Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M10-3190), which action most directly controls the risk related to "DDoS mitigation"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Combine resilient design, upstream scrubbing, rate controls, and rehearsed activation.
Practice
3191
Module 10 · Foundation Domain 3 · Security DDoS mitigation Unanswered

During an authorized retail-company assessment (RET-LAB-M10-3191), which evidence best supports an assessment of "DDoS mitigation"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. Traffic baselines and mitigation records showing attack vectors, volume, and filtered traffic.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3192
Module 10 · Foundation Domain 3 · Security DDoS mitigation Unanswered

During a hospital incident-response exercise (HLT-SOC-M10-3192), which evidence best supports an assessment of "DDoS mitigation"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. Traffic baselines and mitigation records showing attack vectors, volume, and filtered traffic.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3193
Module 10 · Foundation Domain 3 · Security DDoS mitigation Unanswered

During a university cyber-range engagement (EDU-RANGE-M10-3193), which evidence best supports an assessment of "DDoS mitigation"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. Traffic baselines and mitigation records showing attack vectors, volume, and filtered traffic.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3194
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During a financial-services purple-team test (FIN-PT-M10-3194), which evidence best supports an assessment of "DDoS mitigation"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. Traffic baselines and mitigation records showing attack vectors, volume, and filtered traffic.
Practice
3195
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During a cloud startup security audit (CLD-AUDIT-M10-3195), which evidence best supports an assessment of "DDoS mitigation"?

View answer choices
  1. Traffic baselines and mitigation records showing attack vectors, volume, and filtered traffic.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3196
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During a government risk-validation project (GOV-RISK-M10-3196), which evidence best supports an assessment of "DDoS mitigation"?

View answer choices
  1. A risk register with likelihood, impact, owner, treatment, and review date.
  2. Traffic baselines and mitigation records showing attack vectors, volume, and filtered traffic.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3197
Module 10 · Applied Domain 3 · Security DDoS mitigation Unanswered

During an e-commerce application review (ECOM-WEB-M10-3197), which evidence best supports an assessment of "DDoS mitigation"?

View answer choices
  1. Traffic baselines and mitigation records showing attack vectors, volume, and filtered traffic.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3198
Module 10 · Advanced Domain 3 · Security DDoS mitigation Unanswered

During a manufacturing and OT security review (MFG-OT-M10-3198), which evidence best supports an assessment of "DDoS mitigation"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. Traffic baselines and mitigation records showing attack vectors, volume, and filtered traffic.
Practice
3199
Module 10 · Advanced Domain 3 · Security DDoS mitigation Unanswered

During a mobile-services penetration test (MOB-TEST-M10-3199), which evidence best supports an assessment of "DDoS mitigation"?

View answer choices
  1. Traffic baselines and mitigation records showing attack vectors, volume, and filtered traffic.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3200
Module 10 · Advanced Domain 3 · Security DDoS mitigation Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M10-3200), which evidence best supports an assessment of "DDoS mitigation"?

View answer choices
  1. A risk register with likelihood, impact, owner, treatment, and review date.
  2. Traffic baselines and mitigation records showing attack vectors, volume, and filtered traffic.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice