CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 3,351–3,400 of 5,000 matching questions

50 per page
3351
Module 12 · Foundation Domain 3 · Security intrusion detection system Unanswered

During an authorized retail-company assessment (RET-LAB-M12-3351), which evidence best supports an assessment of "intrusion detection system"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. An IDS alert correlated with the triggering traffic and affected asset.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3352
Module 12 · Foundation Domain 3 · Security intrusion detection system Unanswered

During a hospital incident-response exercise (HLT-SOC-M12-3352), which evidence best supports an assessment of "intrusion detection system"?

View answer choices
  1. A risk register with likelihood, impact, owner, treatment, and review date.
  2. An IDS alert correlated with the triggering traffic and affected asset.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3353
Module 12 · Foundation Domain 3 · Security intrusion detection system Unanswered

During a university cyber-range engagement (EDU-RANGE-M12-3353), which evidence best supports an assessment of "intrusion detection system"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An IDS alert correlated with the triggering traffic and affected asset.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3354
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During a financial-services purple-team test (FIN-PT-M12-3354), which evidence best supports an assessment of "intrusion detection system"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. An IDS alert correlated with the triggering traffic and affected asset.
Practice
3355
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During a cloud startup security audit (CLD-AUDIT-M12-3355), which evidence best supports an assessment of "intrusion detection system"?

View answer choices
  1. An IDS alert correlated with the triggering traffic and affected asset.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3356
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During a government risk-validation project (GOV-RISK-M12-3356), which evidence best supports an assessment of "intrusion detection system"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. An IDS alert correlated with the triggering traffic and affected asset.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3357
Module 12 · Applied Domain 3 · Security intrusion detection system Unanswered

During an e-commerce application review (ECOM-WEB-M12-3357), which evidence best supports an assessment of "intrusion detection system"?

View answer choices
  1. An IDS alert correlated with the triggering traffic and affected asset.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3358
Module 12 · Advanced Domain 3 · Security intrusion detection system Unanswered

During a manufacturing and OT security review (MFG-OT-M12-3358), which evidence best supports an assessment of "intrusion detection system"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. An IDS alert correlated with the triggering traffic and affected asset.
Practice
3359
Module 12 · Advanced Domain 3 · Security intrusion detection system Unanswered

During a mobile-services penetration test (MOB-TEST-M12-3359), which evidence best supports an assessment of "intrusion detection system"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. An IDS alert correlated with the triggering traffic and affected asset.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3360
Module 12 · Advanced Domain 3 · Security intrusion detection system Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M12-3360), which evidence best supports an assessment of "intrusion detection system"?

View answer choices
  1. A risk register with likelihood, impact, owner, treatment, and review date.
  2. An IDS alert correlated with the triggering traffic and affected asset.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3361
Module 12 · Foundation Domain 3 · Security intrusion prevention system Unanswered

During an authorized retail-company assessment (RET-LAB-M12-3361), which statement most accurately defines "intrusion prevention system"?

View answer choices
  1. An inline control that can detect and block traffic matching security policy.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3362
Module 12 · Foundation Domain 3 · Security intrusion prevention system Unanswered

During a hospital incident-response exercise (HLT-SOC-M12-3362), which statement most accurately defines "intrusion prevention system"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. An inline control that can detect and block traffic matching security policy.
Practice
3363
Module 12 · Foundation Domain 3 · Security intrusion prevention system Unanswered

During a university cyber-range engagement (EDU-RANGE-M12-3363), which statement most accurately defines "intrusion prevention system"?

View answer choices
  1. An inline control that can detect and block traffic matching security policy.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3364
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During a financial-services purple-team test (FIN-PT-M12-3364), which statement most accurately defines "intrusion prevention system"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. An inline control that can detect and block traffic matching security policy.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3365
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During a cloud startup security audit (CLD-AUDIT-M12-3365), which statement most accurately defines "intrusion prevention system"?

View answer choices
  1. An inline control that can detect and block traffic matching security policy.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3366
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During a government risk-validation project (GOV-RISK-M12-3366), which statement most accurately defines "intrusion prevention system"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. An inline control that can detect and block traffic matching security policy.
Practice
3367
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During an e-commerce application review (ECOM-WEB-M12-3367), which statement most accurately defines "intrusion prevention system"?

View answer choices
  1. An inline control that can detect and block traffic matching security policy.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3368
Module 12 · Advanced Domain 3 · Security intrusion prevention system Unanswered

During a manufacturing and OT security review (MFG-OT-M12-3368), which statement most accurately defines "intrusion prevention system"?

View answer choices
  1. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  2. An inline control that can detect and block traffic matching security policy.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3369
Module 12 · Advanced Domain 3 · Security intrusion prevention system Unanswered

During a mobile-services penetration test (MOB-TEST-M12-3369), which statement most accurately defines "intrusion prevention system"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. An inline control that can detect and block traffic matching security policy.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3370
Module 12 · Advanced Domain 3 · Security intrusion prevention system Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M12-3370), which statement most accurately defines "intrusion prevention system"?

View answer choices
  1. An inline control that can detect and block traffic matching security policy.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3371
Module 12 · Foundation Domain 3 · Security intrusion prevention system Unanswered

During an authorized retail-company assessment (RET-LAB-M12-3371), which risk is most directly associated with "intrusion prevention system"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Incorrect prevention rules can disrupt legitimate traffic or be bypassed through evasions.
Practice
3372
Module 12 · Foundation Domain 3 · Security intrusion prevention system Unanswered

During a hospital incident-response exercise (HLT-SOC-M12-3372), which risk is most directly associated with "intrusion prevention system"?

View answer choices
  1. Incorrect prevention rules can disrupt legitimate traffic or be bypassed through evasions.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3373
Module 12 · Foundation Domain 3 · Security intrusion prevention system Unanswered

During a university cyber-range engagement (EDU-RANGE-M12-3373), which risk is most directly associated with "intrusion prevention system"?

View answer choices
  1. Controls chosen without risk context may protect low-value assets while critical risks remain.
  2. Incorrect prevention rules can disrupt legitimate traffic or be bypassed through evasions.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3374
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During a financial-services purple-team test (FIN-PT-M12-3374), which risk is most directly associated with "intrusion prevention system"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Incorrect prevention rules can disrupt legitimate traffic or be bypassed through evasions.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3375
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During a cloud startup security audit (CLD-AUDIT-M12-3375), which risk is most directly associated with "intrusion prevention system"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Incorrect prevention rules can disrupt legitimate traffic or be bypassed through evasions.
Practice
3376
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During a government risk-validation project (GOV-RISK-M12-3376), which risk is most directly associated with "intrusion prevention system"?

View answer choices
  1. Incorrect prevention rules can disrupt legitimate traffic or be bypassed through evasions.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3377
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During an e-commerce application review (ECOM-WEB-M12-3377), which risk is most directly associated with "intrusion prevention system"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Incorrect prevention rules can disrupt legitimate traffic or be bypassed through evasions.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3378
Module 12 · Advanced Domain 3 · Security intrusion prevention system Unanswered

During a manufacturing and OT security review (MFG-OT-M12-3378), which risk is most directly associated with "intrusion prevention system"?

View answer choices
  1. Incorrect prevention rules can disrupt legitimate traffic or be bypassed through evasions.
  2. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3379
Module 12 · Advanced Domain 3 · Security intrusion prevention system Unanswered

During a mobile-services penetration test (MOB-TEST-M12-3379), which risk is most directly associated with "intrusion prevention system"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Incorrect prevention rules can disrupt legitimate traffic or be bypassed through evasions.
Practice
3380
Module 12 · Advanced Domain 3 · Security intrusion prevention system Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M12-3380), which risk is most directly associated with "intrusion prevention system"?

View answer choices
  1. Incorrect prevention rules can disrupt legitimate traffic or be bypassed through evasions.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3381
Module 12 · Foundation Domain 3 · Security intrusion prevention system Unanswered

During an authorized retail-company assessment (RET-LAB-M12-3381), which action most directly controls the risk related to "intrusion prevention system"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Test signatures, normalize traffic, monitor blocks, and maintain safe bypass procedures.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3382
Module 12 · Foundation Domain 3 · Security intrusion prevention system Unanswered

During a hospital incident-response exercise (HLT-SOC-M12-3382), which action most directly controls the risk related to "intrusion prevention system"?

View answer choices
  1. Test signatures, normalize traffic, monitor blocks, and maintain safe bypass procedures.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3383
Module 12 · Foundation Domain 3 · Security intrusion prevention system Unanswered

During a university cyber-range engagement (EDU-RANGE-M12-3383), which action most directly controls the risk related to "intrusion prevention system"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Test signatures, normalize traffic, monitor blocks, and maintain safe bypass procedures.
Practice
3384
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During a financial-services purple-team test (FIN-PT-M12-3384), which action most directly controls the risk related to "intrusion prevention system"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Test signatures, normalize traffic, monitor blocks, and maintain safe bypass procedures.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3385
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During a cloud startup security audit (CLD-AUDIT-M12-3385), which action most directly controls the risk related to "intrusion prevention system"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Test signatures, normalize traffic, monitor blocks, and maintain safe bypass procedures.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3386
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During a government risk-validation project (GOV-RISK-M12-3386), which action most directly controls the risk related to "intrusion prevention system"?

View answer choices
  1. Test signatures, normalize traffic, monitor blocks, and maintain safe bypass procedures.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3387
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During an e-commerce application review (ECOM-WEB-M12-3387), which action most directly controls the risk related to "intrusion prevention system"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Test signatures, normalize traffic, monitor blocks, and maintain safe bypass procedures.
Practice
3388
Module 12 · Advanced Domain 3 · Security intrusion prevention system Unanswered

During a manufacturing and OT security review (MFG-OT-M12-3388), which action most directly controls the risk related to "intrusion prevention system"?

View answer choices
  1. Test signatures, normalize traffic, monitor blocks, and maintain safe bypass procedures.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3389
Module 12 · Advanced Domain 3 · Security intrusion prevention system Unanswered

During a mobile-services penetration test (MOB-TEST-M12-3389), which action most directly controls the risk related to "intrusion prevention system"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Test signatures, normalize traffic, monitor blocks, and maintain safe bypass procedures.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3390
Module 12 · Advanced Domain 3 · Security intrusion prevention system Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M12-3390), which action most directly controls the risk related to "intrusion prevention system"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Test signatures, normalize traffic, monitor blocks, and maintain safe bypass procedures.
Practice
3391
Module 12 · Foundation Domain 3 · Security intrusion prevention system Unanswered

During an authorized retail-company assessment (RET-LAB-M12-3391), which evidence best supports an assessment of "intrusion prevention system"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. An IPS event showing matched signature, packet context, action, and policy version.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3392
Module 12 · Foundation Domain 3 · Security intrusion prevention system Unanswered

During a hospital incident-response exercise (HLT-SOC-M12-3392), which evidence best supports an assessment of "intrusion prevention system"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. An IPS event showing matched signature, packet context, action, and policy version.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3393
Module 12 · Foundation Domain 3 · Security intrusion prevention system Unanswered

During a university cyber-range engagement (EDU-RANGE-M12-3393), which evidence best supports an assessment of "intrusion prevention system"?

View answer choices
  1. An IPS event showing matched signature, packet context, action, and policy version.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3394
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During a financial-services purple-team test (FIN-PT-M12-3394), which evidence best supports an assessment of "intrusion prevention system"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. An IPS event showing matched signature, packet context, action, and policy version.
Practice
3395
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During a cloud startup security audit (CLD-AUDIT-M12-3395), which evidence best supports an assessment of "intrusion prevention system"?

View answer choices
  1. An IPS event showing matched signature, packet context, action, and policy version.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3396
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During a government risk-validation project (GOV-RISK-M12-3396), which evidence best supports an assessment of "intrusion prevention system"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An IPS event showing matched signature, packet context, action, and policy version.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3397
Module 12 · Applied Domain 3 · Security intrusion prevention system Unanswered

During an e-commerce application review (ECOM-WEB-M12-3397), which evidence best supports an assessment of "intrusion prevention system"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An IPS event showing matched signature, packet context, action, and policy version.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3398
Module 12 · Advanced Domain 3 · Security intrusion prevention system Unanswered

During a manufacturing and OT security review (MFG-OT-M12-3398), which evidence best supports an assessment of "intrusion prevention system"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. An IPS event showing matched signature, packet context, action, and policy version.
Practice
3399
Module 12 · Advanced Domain 3 · Security intrusion prevention system Unanswered

During a mobile-services penetration test (MOB-TEST-M12-3399), which evidence best supports an assessment of "intrusion prevention system"?

View answer choices
  1. An IPS event showing matched signature, packet context, action, and policy version.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3400
Module 12 · Advanced Domain 3 · Security intrusion prevention system Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M12-3400), which evidence best supports an assessment of "intrusion prevention system"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. An IPS event showing matched signature, packet context, action, and policy version.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice