CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 3,201–3,250 of 5,000 matching questions

50 per page
3201
Module 11 · Foundation Domain 1 · Background session hijacking Unanswered

During an authorized retail-company assessment (RET-LAB-M11-3201), which statement most accurately defines "session hijacking"?

View answer choices
  1. Unauthorized takeover or reuse of an authenticated communication session.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
3202
Module 11 · Foundation Domain 1 · Background session hijacking Unanswered

During a hospital incident-response exercise (HLT-SOC-M11-3202), which statement most accurately defines "session hijacking"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. Unauthorized takeover or reuse of an authenticated communication session.
Practice
3203
Module 11 · Foundation Domain 1 · Background session hijacking Unanswered

During a university cyber-range engagement (EDU-RANGE-M11-3203), which statement most accurately defines "session hijacking"?

View answer choices
  1. Unauthorized takeover or reuse of an authenticated communication session.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
3204
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During a financial-services purple-team test (FIN-PT-M11-3204), which statement most accurately defines "session hijacking"?

View answer choices
  1. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  2. Unauthorized takeover or reuse of an authenticated communication session.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
3205
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During a cloud startup security audit (CLD-AUDIT-M11-3205), which statement most accurately defines "session hijacking"?

View answer choices
  1. Unauthorized takeover or reuse of an authenticated communication session.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
3206
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During a government risk-validation project (GOV-RISK-M11-3206), which statement most accurately defines "session hijacking"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. Unauthorized takeover or reuse of an authenticated communication session.
Practice
3207
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During an e-commerce application review (ECOM-WEB-M11-3207), which statement most accurately defines "session hijacking"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. Unauthorized takeover or reuse of an authenticated communication session.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
3208
Module 11 · Advanced Domain 1 · Background session hijacking Unanswered

During a manufacturing and OT security review (MFG-OT-M11-3208), which statement most accurately defines "session hijacking"?

View answer choices
  1. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  2. Unauthorized takeover or reuse of an authenticated communication session.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
3209
Module 11 · Advanced Domain 1 · Background session hijacking Unanswered

During a mobile-services penetration test (MOB-TEST-M11-3209), which statement most accurately defines "session hijacking"?

View answer choices
  1. Unauthorized takeover or reuse of an authenticated communication session.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
3210
Module 11 · Advanced Domain 1 · Background session hijacking Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M11-3210), which statement most accurately defines "session hijacking"?

View answer choices
  1. Unauthorized takeover or reuse of an authenticated communication session.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
3211
Module 11 · Foundation Domain 1 · Background session hijacking Unanswered

During an authorized retail-company assessment (RET-LAB-M11-3211), which risk is most directly associated with "session hijacking"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. A stolen or predicted session token can bypass the normal login step.
Practice
3212
Module 11 · Foundation Domain 1 · Background session hijacking Unanswered

During a hospital incident-response exercise (HLT-SOC-M11-3212), which risk is most directly associated with "session hijacking"?

View answer choices
  1. A stolen or predicted session token can bypass the normal login step.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
3213
Module 11 · Foundation Domain 1 · Background session hijacking Unanswered

During a university cyber-range engagement (EDU-RANGE-M11-3213), which risk is most directly associated with "session hijacking"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. A stolen or predicted session token can bypass the normal login step.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
3214
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During a financial-services purple-team test (FIN-PT-M11-3214), which risk is most directly associated with "session hijacking"?

View answer choices
  1. A stolen or predicted session token can bypass the normal login step.
  2. A control focused on only one objective can leave the other security objectives exposed.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
3215
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During a cloud startup security audit (CLD-AUDIT-M11-3215), which risk is most directly associated with "session hijacking"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. A stolen or predicted session token can bypass the normal login step.
Practice
3216
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During a government risk-validation project (GOV-RISK-M11-3216), which risk is most directly associated with "session hijacking"?

View answer choices
  1. A stolen or predicted session token can bypass the normal login step.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
3217
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During an e-commerce application review (ECOM-WEB-M11-3217), which risk is most directly associated with "session hijacking"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. A stolen or predicted session token can bypass the normal login step.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
3218
Module 11 · Advanced Domain 1 · Background session hijacking Unanswered

During a manufacturing and OT security review (MFG-OT-M11-3218), which risk is most directly associated with "session hijacking"?

View answer choices
  1. A stolen or predicted session token can bypass the normal login step.
  2. A control focused on only one objective can leave the other security objectives exposed.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
3219
Module 11 · Advanced Domain 1 · Background session hijacking Unanswered

During a mobile-services penetration test (MOB-TEST-M11-3219), which risk is most directly associated with "session hijacking"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. A stolen or predicted session token can bypass the normal login step.
Practice
3220
Module 11 · Advanced Domain 1 · Background session hijacking Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M11-3220), which risk is most directly associated with "session hijacking"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. A stolen or predicted session token can bypass the normal login step.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
3221
Module 11 · Foundation Domain 1 · Background session hijacking Unanswered

During an authorized retail-company assessment (RET-LAB-M11-3221), which action most directly controls the risk related to "session hijacking"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Protect tokens with TLS, secure cookie attributes, rotation, and reauthentication.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
3222
Module 11 · Foundation Domain 1 · Background session hijacking Unanswered

During a hospital incident-response exercise (HLT-SOC-M11-3222), which action most directly controls the risk related to "session hijacking"?

View answer choices
  1. Protect tokens with TLS, secure cookie attributes, rotation, and reauthentication.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
3223
Module 11 · Foundation Domain 1 · Background session hijacking Unanswered

During a university cyber-range engagement (EDU-RANGE-M11-3223), which action most directly controls the risk related to "session hijacking"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Protect tokens with TLS, secure cookie attributes, rotation, and reauthentication.
Practice
3224
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During a financial-services purple-team test (FIN-PT-M11-3224), which action most directly controls the risk related to "session hijacking"?

View answer choices
  1. Protect tokens with TLS, secure cookie attributes, rotation, and reauthentication.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
3225
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During a cloud startup security audit (CLD-AUDIT-M11-3225), which action most directly controls the risk related to "session hijacking"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Protect tokens with TLS, secure cookie attributes, rotation, and reauthentication.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
3226
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During a government risk-validation project (GOV-RISK-M11-3226), which action most directly controls the risk related to "session hijacking"?

View answer choices
  1. Protect tokens with TLS, secure cookie attributes, rotation, and reauthentication.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
3227
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During an e-commerce application review (ECOM-WEB-M11-3227), which action most directly controls the risk related to "session hijacking"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Protect tokens with TLS, secure cookie attributes, rotation, and reauthentication.
Practice
3228
Module 11 · Advanced Domain 1 · Background session hijacking Unanswered

During a manufacturing and OT security review (MFG-OT-M11-3228), which action most directly controls the risk related to "session hijacking"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Protect tokens with TLS, secure cookie attributes, rotation, and reauthentication.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
3229
Module 11 · Advanced Domain 1 · Background session hijacking Unanswered

During a mobile-services penetration test (MOB-TEST-M11-3229), which action most directly controls the risk related to "session hijacking"?

View answer choices
  1. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  2. Protect tokens with TLS, secure cookie attributes, rotation, and reauthentication.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
3230
Module 11 · Advanced Domain 1 · Background session hijacking Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M11-3230), which action most directly controls the risk related to "session hijacking"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Protect tokens with TLS, secure cookie attributes, rotation, and reauthentication.
Practice
3231
Module 11 · Foundation Domain 1 · Background session hijacking Unanswered

During an authorized retail-company assessment (RET-LAB-M11-3231), which evidence best supports an assessment of "session hijacking"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A risk register linking assets to CIA impact ratings.
  3. A session identifier used from an unexpected client, location, or device context.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
3232
Module 11 · Foundation Domain 1 · Background session hijacking Unanswered

During a hospital incident-response exercise (HLT-SOC-M11-3232), which evidence best supports an assessment of "session hijacking"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. A session identifier used from an unexpected client, location, or device context.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
3233
Module 11 · Foundation Domain 1 · Background session hijacking Unanswered

During a university cyber-range engagement (EDU-RANGE-M11-3233), which evidence best supports an assessment of "session hijacking"?

View answer choices
  1. A session identifier used from an unexpected client, location, or device context.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. A risk register linking assets to CIA impact ratings.
Practice
3234
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During a financial-services purple-team test (FIN-PT-M11-3234), which evidence best supports an assessment of "session hijacking"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A session identifier used from an unexpected client, location, or device context.
Practice
3235
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During a cloud startup security audit (CLD-AUDIT-M11-3235), which evidence best supports an assessment of "session hijacking"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A risk register linking assets to CIA impact ratings.
  3. A session identifier used from an unexpected client, location, or device context.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
3236
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During a government risk-validation project (GOV-RISK-M11-3236), which evidence best supports an assessment of "session hijacking"?

View answer choices
  1. A detection matrix showing covered and uncovered ATT&CK techniques.
  2. A session identifier used from an unexpected client, location, or device context.
  3. A risk register linking assets to CIA impact ratings.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
3237
Module 11 · Applied Domain 1 · Background session hijacking Unanswered

During an e-commerce application review (ECOM-WEB-M11-3237), which evidence best supports an assessment of "session hijacking"?

View answer choices
  1. A session identifier used from an unexpected client, location, or device context.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A risk register linking assets to CIA impact ratings.
Practice
3238
Module 11 · Advanced Domain 1 · Background session hijacking Unanswered

During a manufacturing and OT security review (MFG-OT-M11-3238), which evidence best supports an assessment of "session hijacking"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. A risk register linking assets to CIA impact ratings.
  4. A session identifier used from an unexpected client, location, or device context.
Practice
3239
Module 11 · Advanced Domain 1 · Background session hijacking Unanswered

During a mobile-services penetration test (MOB-TEST-M11-3239), which evidence best supports an assessment of "session hijacking"?

View answer choices
  1. A session identifier used from an unexpected client, location, or device context.
  2. A risk register linking assets to CIA impact ratings.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
3240
Module 11 · Advanced Domain 1 · Background session hijacking Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M11-3240), which evidence best supports an assessment of "session hijacking"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. A session identifier used from an unexpected client, location, or device context.
  4. A risk register linking assets to CIA impact ratings.
Practice
3241
Module 11 · Foundation Domain 3 · Security secure session management Unanswered

During an authorized retail-company assessment (RET-LAB-M11-3241), which statement most accurately defines "secure session management"?

View answer choices
  1. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  2. Controls that create, protect, rotate, expire, and revoke authenticated sessions.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3242
Module 11 · Foundation Domain 3 · Security secure session management Unanswered

During a hospital incident-response exercise (HLT-SOC-M11-3242), which statement most accurately defines "secure session management"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Controls that create, protect, rotate, expire, and revoke authenticated sessions.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3243
Module 11 · Foundation Domain 3 · Security secure session management Unanswered

During a university cyber-range engagement (EDU-RANGE-M11-3243), which statement most accurately defines "secure session management"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Controls that create, protect, rotate, expire, and revoke authenticated sessions.
Practice
3244
Module 11 · Applied Domain 3 · Security secure session management Unanswered

During a financial-services purple-team test (FIN-PT-M11-3244), which statement most accurately defines "secure session management"?

View answer choices
  1. Controls that create, protect, rotate, expire, and revoke authenticated sessions.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3245
Module 11 · Applied Domain 3 · Security secure session management Unanswered

During a cloud startup security audit (CLD-AUDIT-M11-3245), which statement most accurately defines "secure session management"?

View answer choices
  1. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  2. Controls that create, protect, rotate, expire, and revoke authenticated sessions.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3246
Module 11 · Applied Domain 3 · Security secure session management Unanswered

During a government risk-validation project (GOV-RISK-M11-3246), which statement most accurately defines "secure session management"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Controls that create, protect, rotate, expire, and revoke authenticated sessions.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3247
Module 11 · Applied Domain 3 · Security secure session management Unanswered

During an e-commerce application review (ECOM-WEB-M11-3247), which statement most accurately defines "secure session management"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Controls that create, protect, rotate, expire, and revoke authenticated sessions.
Practice
3248
Module 11 · Advanced Domain 3 · Security secure session management Unanswered

During a manufacturing and OT security review (MFG-OT-M11-3248), which statement most accurately defines "secure session management"?

View answer choices
  1. Controls that create, protect, rotate, expire, and revoke authenticated sessions.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3249
Module 11 · Advanced Domain 3 · Security secure session management Unanswered

During a mobile-services penetration test (MOB-TEST-M11-3249), which statement most accurately defines "secure session management"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Controls that create, protect, rotate, expire, and revoke authenticated sessions.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3250
Module 11 · Advanced Domain 3 · Security secure session management Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M11-3250), which statement most accurately defines "secure session management"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Controls that create, protect, rotate, expire, and revoke authenticated sessions.
Practice