CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 3,301–3,350 of 5,000 matching questions

50 per page
3301
Module 12 · Foundation Domain 3 · Security honeypot Unanswered

During an authorized retail-company assessment (RET-LAB-M12-3301), which action most directly controls the risk related to "honeypot"?

View answer choices
  1. Isolate the decoy, collect high-quality telemetry, and define response procedures.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3302
Module 12 · Foundation Domain 3 · Security honeypot Unanswered

During a hospital incident-response exercise (HLT-SOC-M12-3302), which action most directly controls the risk related to "honeypot"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Isolate the decoy, collect high-quality telemetry, and define response procedures.
Practice
3303
Module 12 · Foundation Domain 3 · Security honeypot Unanswered

During a university cyber-range engagement (EDU-RANGE-M12-3303), which action most directly controls the risk related to "honeypot"?

View answer choices
  1. Isolate the decoy, collect high-quality telemetry, and define response procedures.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3304
Module 12 · Applied Domain 3 · Security honeypot Unanswered

During a financial-services purple-team test (FIN-PT-M12-3304), which action most directly controls the risk related to "honeypot"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Isolate the decoy, collect high-quality telemetry, and define response procedures.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3305
Module 12 · Applied Domain 3 · Security honeypot Unanswered

During a cloud startup security audit (CLD-AUDIT-M12-3305), which action most directly controls the risk related to "honeypot"?

View answer choices
  1. Isolate the decoy, collect high-quality telemetry, and define response procedures.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3306
Module 12 · Applied Domain 3 · Security honeypot Unanswered

During a government risk-validation project (GOV-RISK-M12-3306), which action most directly controls the risk related to "honeypot"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Isolate the decoy, collect high-quality telemetry, and define response procedures.
Practice
3307
Module 12 · Applied Domain 3 · Security honeypot Unanswered

During an e-commerce application review (ECOM-WEB-M12-3307), which action most directly controls the risk related to "honeypot"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Isolate the decoy, collect high-quality telemetry, and define response procedures.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3308
Module 12 · Advanced Domain 3 · Security honeypot Unanswered

During a manufacturing and OT security review (MFG-OT-M12-3308), which action most directly controls the risk related to "honeypot"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Isolate the decoy, collect high-quality telemetry, and define response procedures.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3309
Module 12 · Advanced Domain 3 · Security honeypot Unanswered

During a mobile-services penetration test (MOB-TEST-M12-3309), which action most directly controls the risk related to "honeypot"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Isolate the decoy, collect high-quality telemetry, and define response procedures.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3310
Module 12 · Advanced Domain 3 · Security honeypot Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M12-3310), which action most directly controls the risk related to "honeypot"?

View answer choices
  1. Isolate the decoy, collect high-quality telemetry, and define response procedures.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3311
Module 12 · Foundation Domain 3 · Security honeypot Unanswered

During an authorized retail-company assessment (RET-LAB-M12-3311), which evidence best supports an assessment of "honeypot"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. Interaction logs from a system with no legitimate business users.
Practice
3312
Module 12 · Foundation Domain 3 · Security honeypot Unanswered

During a hospital incident-response exercise (HLT-SOC-M12-3312), which evidence best supports an assessment of "honeypot"?

View answer choices
  1. Interaction logs from a system with no legitimate business users.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3313
Module 12 · Foundation Domain 3 · Security honeypot Unanswered

During a university cyber-range engagement (EDU-RANGE-M12-3313), which evidence best supports an assessment of "honeypot"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. Interaction logs from a system with no legitimate business users.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3314
Module 12 · Applied Domain 3 · Security honeypot Unanswered

During a financial-services purple-team test (FIN-PT-M12-3314), which evidence best supports an assessment of "honeypot"?

View answer choices
  1. Interaction logs from a system with no legitimate business users.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3315
Module 12 · Applied Domain 3 · Security honeypot Unanswered

During a cloud startup security audit (CLD-AUDIT-M12-3315), which evidence best supports an assessment of "honeypot"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. Interaction logs from a system with no legitimate business users.
Practice
3316
Module 12 · Applied Domain 3 · Security honeypot Unanswered

During a government risk-validation project (GOV-RISK-M12-3316), which evidence best supports an assessment of "honeypot"?

View answer choices
  1. Interaction logs from a system with no legitimate business users.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3317
Module 12 · Applied Domain 3 · Security honeypot Unanswered

During an e-commerce application review (ECOM-WEB-M12-3317), which evidence best supports an assessment of "honeypot"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. Interaction logs from a system with no legitimate business users.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3318
Module 12 · Advanced Domain 3 · Security honeypot Unanswered

During a manufacturing and OT security review (MFG-OT-M12-3318), which evidence best supports an assessment of "honeypot"?

View answer choices
  1. Interaction logs from a system with no legitimate business users.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3319
Module 12 · Advanced Domain 3 · Security honeypot Unanswered

During a mobile-services penetration test (MOB-TEST-M12-3319), which evidence best supports an assessment of "honeypot"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. Interaction logs from a system with no legitimate business users.
Practice
3320
Module 12 · Advanced Domain 3 · Security honeypot Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M12-3320), which evidence best supports an assessment of "honeypot"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. Interaction logs from a system with no legitimate business users.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3321
Module 12 · Foundation Domain 3 · Security intrusion detection system Unanswered

During an authorized retail-company assessment (RET-LAB-M12-3321), which statement most accurately defines "intrusion detection system"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. A control that monitors activity and generates alerts for suspicious patterns without necessarily blocking them.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3322
Module 12 · Foundation Domain 3 · Security intrusion detection system Unanswered

During a hospital incident-response exercise (HLT-SOC-M12-3322), which statement most accurately defines "intrusion detection system"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. A control that monitors activity and generates alerts for suspicious patterns without necessarily blocking them.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3323
Module 12 · Foundation Domain 3 · Security intrusion detection system Unanswered

During a university cyber-range engagement (EDU-RANGE-M12-3323), which statement most accurately defines "intrusion detection system"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. A control that monitors activity and generates alerts for suspicious patterns without necessarily blocking them.
Practice
3324
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During a financial-services purple-team test (FIN-PT-M12-3324), which statement most accurately defines "intrusion detection system"?

View answer choices
  1. A control that monitors activity and generates alerts for suspicious patterns without necessarily blocking them.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3325
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During a cloud startup security audit (CLD-AUDIT-M12-3325), which statement most accurately defines "intrusion detection system"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. A control that monitors activity and generates alerts for suspicious patterns without necessarily blocking them.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3326
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During a government risk-validation project (GOV-RISK-M12-3326), which statement most accurately defines "intrusion detection system"?

View answer choices
  1. A control that monitors activity and generates alerts for suspicious patterns without necessarily blocking them.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3327
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During an e-commerce application review (ECOM-WEB-M12-3327), which statement most accurately defines "intrusion detection system"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. A control that monitors activity and generates alerts for suspicious patterns without necessarily blocking them.
Practice
3328
Module 12 · Advanced Domain 3 · Security intrusion detection system Unanswered

During a manufacturing and OT security review (MFG-OT-M12-3328), which statement most accurately defines "intrusion detection system"?

View answer choices
  1. A control that monitors activity and generates alerts for suspicious patterns without necessarily blocking them.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3329
Module 12 · Advanced Domain 3 · Security intrusion detection system Unanswered

During a mobile-services penetration test (MOB-TEST-M12-3329), which statement most accurately defines "intrusion detection system"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. A control that monitors activity and generates alerts for suspicious patterns without necessarily blocking them.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3330
Module 12 · Advanced Domain 3 · Security intrusion detection system Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M12-3330), which statement most accurately defines "intrusion detection system"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. A control that monitors activity and generates alerts for suspicious patterns without necessarily blocking them.
Practice
3331
Module 12 · Foundation Domain 3 · Security intrusion detection system Unanswered

During an authorized retail-company assessment (RET-LAB-M12-3331), which risk is most directly associated with "intrusion detection system"?

View answer choices
  1. Untuned rules create false positives, while missing visibility creates false negatives.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3332
Module 12 · Foundation Domain 3 · Security intrusion detection system Unanswered

During a hospital incident-response exercise (HLT-SOC-M12-3332), which risk is most directly associated with "intrusion detection system"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Untuned rules create false positives, while missing visibility creates false negatives.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3333
Module 12 · Foundation Domain 3 · Security intrusion detection system Unanswered

During a university cyber-range engagement (EDU-RANGE-M12-3333), which risk is most directly associated with "intrusion detection system"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Untuned rules create false positives, while missing visibility creates false negatives.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3334
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During a financial-services purple-team test (FIN-PT-M12-3334), which risk is most directly associated with "intrusion detection system"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Untuned rules create false positives, while missing visibility creates false negatives.
Practice
3335
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During a cloud startup security audit (CLD-AUDIT-M12-3335), which risk is most directly associated with "intrusion detection system"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Untuned rules create false positives, while missing visibility creates false negatives.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3336
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During a government risk-validation project (GOV-RISK-M12-3336), which risk is most directly associated with "intrusion detection system"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Untuned rules create false positives, while missing visibility creates false negatives.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3337
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During an e-commerce application review (ECOM-WEB-M12-3337), which risk is most directly associated with "intrusion detection system"?

View answer choices
  1. Untuned rules create false positives, while missing visibility creates false negatives.
  2. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3338
Module 12 · Advanced Domain 3 · Security intrusion detection system Unanswered

During a manufacturing and OT security review (MFG-OT-M12-3338), which risk is most directly associated with "intrusion detection system"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Untuned rules create false positives, while missing visibility creates false negatives.
Practice
3339
Module 12 · Advanced Domain 3 · Security intrusion detection system Unanswered

During a mobile-services penetration test (MOB-TEST-M12-3339), which risk is most directly associated with "intrusion detection system"?

View answer choices
  1. Untuned rules create false positives, while missing visibility creates false negatives.
  2. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3340
Module 12 · Advanced Domain 3 · Security intrusion detection system Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M12-3340), which risk is most directly associated with "intrusion detection system"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Untuned rules create false positives, while missing visibility creates false negatives.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3341
Module 12 · Foundation Domain 3 · Security intrusion detection system Unanswered

During an authorized retail-company assessment (RET-LAB-M12-3341), which action most directly controls the risk related to "intrusion detection system"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Place sensors strategically, tune rules, and validate alerts against packet and host evidence.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3342
Module 12 · Foundation Domain 3 · Security intrusion detection system Unanswered

During a hospital incident-response exercise (HLT-SOC-M12-3342), which action most directly controls the risk related to "intrusion detection system"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Place sensors strategically, tune rules, and validate alerts against packet and host evidence.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3343
Module 12 · Foundation Domain 3 · Security intrusion detection system Unanswered

During a university cyber-range engagement (EDU-RANGE-M12-3343), which action most directly controls the risk related to "intrusion detection system"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Place sensors strategically, tune rules, and validate alerts against packet and host evidence.
Practice
3344
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During a financial-services purple-team test (FIN-PT-M12-3344), which action most directly controls the risk related to "intrusion detection system"?

View answer choices
  1. Place sensors strategically, tune rules, and validate alerts against packet and host evidence.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3345
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During a cloud startup security audit (CLD-AUDIT-M12-3345), which action most directly controls the risk related to "intrusion detection system"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Place sensors strategically, tune rules, and validate alerts against packet and host evidence.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3346
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During a government risk-validation project (GOV-RISK-M12-3346), which action most directly controls the risk related to "intrusion detection system"?

View answer choices
  1. Place sensors strategically, tune rules, and validate alerts against packet and host evidence.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3347
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During an e-commerce application review (ECOM-WEB-M12-3347), which action most directly controls the risk related to "intrusion detection system"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Place sensors strategically, tune rules, and validate alerts against packet and host evidence.
Practice
3348
Module 12 · Advanced Domain 3 · Security intrusion detection system Unanswered

During a manufacturing and OT security review (MFG-OT-M12-3348), which action most directly controls the risk related to "intrusion detection system"?

View answer choices
  1. Place sensors strategically, tune rules, and validate alerts against packet and host evidence.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3349
Module 12 · Advanced Domain 3 · Security intrusion detection system Unanswered

During a mobile-services penetration test (MOB-TEST-M12-3349), which action most directly controls the risk related to "intrusion detection system"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Place sensors strategically, tune rules, and validate alerts against packet and host evidence.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3350
Module 12 · Advanced Domain 3 · Security intrusion detection system Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M12-3350), which action most directly controls the risk related to "intrusion detection system"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Place sensors strategically, tune rules, and validate alerts against packet and host evidence.
Practice