CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 3,451–3,500 of 5,000 matching questions

50 per page
3451
Module 12 · Foundation Domain 4 · Tools / Systems / Programs Snort Unanswered

During an authorized retail-company assessment (RET-LAB-M12-3451), which risk is most directly associated with "Snort"?

View answer choices
  1. Poor placement or tuning can miss attacks or generate excessive alerts.
  2. Automated modules can query third parties or collect data outside scope.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3452
Module 12 · Foundation Domain 4 · Tools / Systems / Programs Snort Unanswered

During a hospital incident-response exercise (HLT-SOC-M12-3452), which risk is most directly associated with "Snort"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Poor placement or tuning can miss attacks or generate excessive alerts.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Automated modules can query third parties or collect data outside scope.
Practice
3453
Module 12 · Foundation Domain 4 · Tools / Systems / Programs Snort Unanswered

During a university cyber-range engagement (EDU-RANGE-M12-3453), which risk is most directly associated with "Snort"?

View answer choices
  1. Poor placement or tuning can miss attacks or generate excessive alerts.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3454
Module 12 · Applied Domain 4 · Tools / Systems / Programs Snort Unanswered

During a financial-services purple-team test (FIN-PT-M12-3454), which risk is most directly associated with "Snort"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Automated modules can query third parties or collect data outside scope.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Poor placement or tuning can miss attacks or generate excessive alerts.
Practice
3455
Module 12 · Applied Domain 4 · Tools / Systems / Programs Snort Unanswered

During a cloud startup security audit (CLD-AUDIT-M12-3455), which risk is most directly associated with "Snort"?

View answer choices
  1. Poor placement or tuning can miss attacks or generate excessive alerts.
  2. Automated modules can query third parties or collect data outside scope.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3456
Module 12 · Applied Domain 4 · Tools / Systems / Programs Snort Unanswered

During a government risk-validation project (GOV-RISK-M12-3456), which risk is most directly associated with "Snort"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Poor placement or tuning can miss attacks or generate excessive alerts.
  4. Automated modules can query third parties or collect data outside scope.
Practice
3457
Module 12 · Applied Domain 4 · Tools / Systems / Programs Snort Unanswered

During an e-commerce application review (ECOM-WEB-M12-3457), which risk is most directly associated with "Snort"?

View answer choices
  1. Poor placement or tuning can miss attacks or generate excessive alerts.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3458
Module 12 · Advanced Domain 4 · Tools / Systems / Programs Snort Unanswered

During a manufacturing and OT security review (MFG-OT-M12-3458), which risk is most directly associated with "Snort"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Poor placement or tuning can miss attacks or generate excessive alerts.
Practice
3459
Module 12 · Advanced Domain 4 · Tools / Systems / Programs Snort Unanswered

During a mobile-services penetration test (MOB-TEST-M12-3459), which risk is most directly associated with "Snort"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Poor placement or tuning can miss attacks or generate excessive alerts.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3460
Module 12 · Advanced Domain 4 · Tools / Systems / Programs Snort Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M12-3460), which risk is most directly associated with "Snort"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Poor placement or tuning can miss attacks or generate excessive alerts.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Automated modules can query third parties or collect data outside scope.
Practice
3461
Module 12 · Foundation Domain 4 · Tools / Systems / Programs Snort Unanswered

During an authorized retail-company assessment (RET-LAB-M12-3461), which action most directly controls the risk related to "Snort"?

View answer choices
  1. Tune rules, update signatures, normalize traffic, and validate sensor visibility.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3462
Module 12 · Foundation Domain 4 · Tools / Systems / Programs Snort Unanswered

During a hospital incident-response exercise (HLT-SOC-M12-3462), which action most directly controls the risk related to "Snort"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Tune rules, update signatures, normalize traffic, and validate sensor visibility.
Practice
3463
Module 12 · Foundation Domain 4 · Tools / Systems / Programs Snort Unanswered

During a university cyber-range engagement (EDU-RANGE-M12-3463), which action most directly controls the risk related to "Snort"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Tune rules, update signatures, normalize traffic, and validate sensor visibility.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3464
Module 12 · Applied Domain 4 · Tools / Systems / Programs Snort Unanswered

During a financial-services purple-team test (FIN-PT-M12-3464), which action most directly controls the risk related to "Snort"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Tune rules, update signatures, normalize traffic, and validate sensor visibility.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3465
Module 12 · Applied Domain 4 · Tools / Systems / Programs Snort Unanswered

During a cloud startup security audit (CLD-AUDIT-M12-3465), which action most directly controls the risk related to "Snort"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Tune rules, update signatures, normalize traffic, and validate sensor visibility.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3466
Module 12 · Applied Domain 4 · Tools / Systems / Programs Snort Unanswered

During a government risk-validation project (GOV-RISK-M12-3466), which action most directly controls the risk related to "Snort"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Tune rules, update signatures, normalize traffic, and validate sensor visibility.
Practice
3467
Module 12 · Applied Domain 4 · Tools / Systems / Programs Snort Unanswered

During an e-commerce application review (ECOM-WEB-M12-3467), which action most directly controls the risk related to "Snort"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Tune rules, update signatures, normalize traffic, and validate sensor visibility.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3468
Module 12 · Advanced Domain 4 · Tools / Systems / Programs Snort Unanswered

During a manufacturing and OT security review (MFG-OT-M12-3468), which action most directly controls the risk related to "Snort"?

View answer choices
  1. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  2. Tune rules, update signatures, normalize traffic, and validate sensor visibility.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3469
Module 12 · Advanced Domain 4 · Tools / Systems / Programs Snort Unanswered

During a mobile-services penetration test (MOB-TEST-M12-3469), which action most directly controls the risk related to "Snort"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Tune rules, update signatures, normalize traffic, and validate sensor visibility.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3470
Module 12 · Advanced Domain 4 · Tools / Systems / Programs Snort Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M12-3470), which action most directly controls the risk related to "Snort"?

View answer choices
  1. Tune rules, update signatures, normalize traffic, and validate sensor visibility.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3471
Module 12 · Foundation Domain 4 · Tools / Systems / Programs Snort Unanswered

During an authorized retail-company assessment (RET-LAB-M12-3471), which evidence best supports an assessment of "Snort"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A Snort alert matched to packet evidence and the exact rule revision.
Practice
3472
Module 12 · Foundation Domain 4 · Tools / Systems / Programs Snort Unanswered

During a hospital incident-response exercise (HLT-SOC-M12-3472), which evidence best supports an assessment of "Snort"?

View answer choices
  1. A Snort alert matched to packet evidence and the exact rule revision.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A relationship graph retaining sources and transformation history.
Practice
3473
Module 12 · Foundation Domain 4 · Tools / Systems / Programs Snort Unanswered

During a university cyber-range engagement (EDU-RANGE-M12-3473), which evidence best supports an assessment of "Snort"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. A Snort alert matched to packet evidence and the exact rule revision.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
3474
Module 12 · Applied Domain 4 · Tools / Systems / Programs Snort Unanswered

During a financial-services purple-team test (FIN-PT-M12-3474), which evidence best supports an assessment of "Snort"?

View answer choices
  1. A Snort alert matched to packet evidence and the exact rule revision.
  2. A relationship graph retaining sources and transformation history.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Search results validated against the organization’s current external inventory.
Practice
3475
Module 12 · Applied Domain 4 · Tools / Systems / Programs Snort Unanswered

During a cloud startup security audit (CLD-AUDIT-M12-3475), which evidence best supports an assessment of "Snort"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A Snort alert matched to packet evidence and the exact rule revision.
Practice
3476
Module 12 · Applied Domain 4 · Tools / Systems / Programs Snort Unanswered

During a government risk-validation project (GOV-RISK-M12-3476), which evidence best supports an assessment of "Snort"?

View answer choices
  1. A Snort alert matched to packet evidence and the exact rule revision.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A relationship graph retaining sources and transformation history.
Practice
3477
Module 12 · Applied Domain 4 · Tools / Systems / Programs Snort Unanswered

During an e-commerce application review (ECOM-WEB-M12-3477), which evidence best supports an assessment of "Snort"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. A Snort alert matched to packet evidence and the exact rule revision.
  3. Search results validated against the organization’s current external inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
3478
Module 12 · Advanced Domain 4 · Tools / Systems / Programs Snort Unanswered

During a manufacturing and OT security review (MFG-OT-M12-3478), which evidence best supports an assessment of "Snort"?

View answer choices
  1. A Snort alert matched to packet evidence and the exact rule revision.
  2. A relationship graph retaining sources and transformation history.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Search results validated against the organization’s current external inventory.
Practice
3479
Module 12 · Advanced Domain 4 · Tools / Systems / Programs Snort Unanswered

During a mobile-services penetration test (MOB-TEST-M12-3479), which evidence best supports an assessment of "Snort"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A Snort alert matched to packet evidence and the exact rule revision.
Practice
3480
Module 12 · Advanced Domain 4 · Tools / Systems / Programs Snort Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M12-3480), which evidence best supports an assessment of "Snort"?

View answer choices
  1. A Snort alert matched to packet evidence and the exact rule revision.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A relationship graph retaining sources and transformation history.
Practice
3481
Module 13 · Foundation Domain 3 · Security secure web-server configuration Unanswered

During an authorized retail-company assessment (RET-LAB-M13-3481), which statement most accurately defines "secure web-server configuration"?

View answer choices
  1. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  2. Hardening that removes unsafe defaults, limits features, patches software, and protects transport.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3482
Module 13 · Foundation Domain 3 · Security secure web-server configuration Unanswered

During a hospital incident-response exercise (HLT-SOC-M13-3482), which statement most accurately defines "secure web-server configuration"?

View answer choices
  1. Hardening that removes unsafe defaults, limits features, patches software, and protects transport.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3483
Module 13 · Foundation Domain 3 · Security secure web-server configuration Unanswered

During a university cyber-range engagement (EDU-RANGE-M13-3483), which statement most accurately defines "secure web-server configuration"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Hardening that removes unsafe defaults, limits features, patches software, and protects transport.
Practice
3484
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During a financial-services purple-team test (FIN-PT-M13-3484), which statement most accurately defines "secure web-server configuration"?

View answer choices
  1. Hardening that removes unsafe defaults, limits features, patches software, and protects transport.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3485
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During a cloud startup security audit (CLD-AUDIT-M13-3485), which statement most accurately defines "secure web-server configuration"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Hardening that removes unsafe defaults, limits features, patches software, and protects transport.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3486
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During a government risk-validation project (GOV-RISK-M13-3486), which statement most accurately defines "secure web-server configuration"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Hardening that removes unsafe defaults, limits features, patches software, and protects transport.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3487
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During an e-commerce application review (ECOM-WEB-M13-3487), which statement most accurately defines "secure web-server configuration"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Hardening that removes unsafe defaults, limits features, patches software, and protects transport.
Practice
3488
Module 13 · Advanced Domain 3 · Security secure web-server configuration Unanswered

During a manufacturing and OT security review (MFG-OT-M13-3488), which statement most accurately defines "secure web-server configuration"?

View answer choices
  1. Hardening that removes unsafe defaults, limits features, patches software, and protects transport.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3489
Module 13 · Advanced Domain 3 · Security secure web-server configuration Unanswered

During a mobile-services penetration test (MOB-TEST-M13-3489), which statement most accurately defines "secure web-server configuration"?

View answer choices
  1. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  2. Hardening that removes unsafe defaults, limits features, patches software, and protects transport.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3490
Module 13 · Advanced Domain 3 · Security secure web-server configuration Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M13-3490), which statement most accurately defines "secure web-server configuration"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Hardening that removes unsafe defaults, limits features, patches software, and protects transport.
Practice
3491
Module 13 · Foundation Domain 3 · Security secure web-server configuration Unanswered

During an authorized retail-company assessment (RET-LAB-M13-3491), which risk is most directly associated with "secure web-server configuration"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Default content, weak TLS, verbose errors, and unnecessary modules disclose or expose attack paths.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3492
Module 13 · Foundation Domain 3 · Security secure web-server configuration Unanswered

During a hospital incident-response exercise (HLT-SOC-M13-3492), which risk is most directly associated with "secure web-server configuration"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Default content, weak TLS, verbose errors, and unnecessary modules disclose or expose attack paths.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3493
Module 13 · Foundation Domain 3 · Security secure web-server configuration Unanswered

During a university cyber-range engagement (EDU-RANGE-M13-3493), which risk is most directly associated with "secure web-server configuration"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Default content, weak TLS, verbose errors, and unnecessary modules disclose or expose attack paths.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3494
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During a financial-services purple-team test (FIN-PT-M13-3494), which risk is most directly associated with "secure web-server configuration"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Default content, weak TLS, verbose errors, and unnecessary modules disclose or expose attack paths.
Practice
3495
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During a cloud startup security audit (CLD-AUDIT-M13-3495), which risk is most directly associated with "secure web-server configuration"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Default content, weak TLS, verbose errors, and unnecessary modules disclose or expose attack paths.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3496
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During a government risk-validation project (GOV-RISK-M13-3496), which risk is most directly associated with "secure web-server configuration"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Default content, weak TLS, verbose errors, and unnecessary modules disclose or expose attack paths.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3497
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During an e-commerce application review (ECOM-WEB-M13-3497), which risk is most directly associated with "secure web-server configuration"?

View answer choices
  1. Default content, weak TLS, verbose errors, and unnecessary modules disclose or expose attack paths.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3498
Module 13 · Advanced Domain 3 · Security secure web-server configuration Unanswered

During a manufacturing and OT security review (MFG-OT-M13-3498), which risk is most directly associated with "secure web-server configuration"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Default content, weak TLS, verbose errors, and unnecessary modules disclose or expose attack paths.
Practice
3499
Module 13 · Advanced Domain 3 · Security secure web-server configuration Unanswered

During a mobile-services penetration test (MOB-TEST-M13-3499), which risk is most directly associated with "secure web-server configuration"?

View answer choices
  1. Default content, weak TLS, verbose errors, and unnecessary modules disclose or expose attack paths.
  2. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3500
Module 13 · Advanced Domain 3 · Security secure web-server configuration Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M13-3500), which risk is most directly associated with "secure web-server configuration"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Default content, weak TLS, verbose errors, and unnecessary modules disclose or expose attack paths.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice