CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 3,501–3,550 of 5,000 matching questions

50 per page
3501
Module 13 · Foundation Domain 3 · Security secure web-server configuration Unanswered

During an authorized retail-company assessment (RET-LAB-M13-3501), which action most directly controls the risk related to "secure web-server configuration"?

View answer choices
  1. Use hardened baselines, patching, minimal modules, secure TLS, and configuration monitoring.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3502
Module 13 · Foundation Domain 3 · Security secure web-server configuration Unanswered

During a hospital incident-response exercise (HLT-SOC-M13-3502), which action most directly controls the risk related to "secure web-server configuration"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Use hardened baselines, patching, minimal modules, secure TLS, and configuration monitoring.
Practice
3503
Module 13 · Foundation Domain 3 · Security secure web-server configuration Unanswered

During a university cyber-range engagement (EDU-RANGE-M13-3503), which action most directly controls the risk related to "secure web-server configuration"?

View answer choices
  1. Use hardened baselines, patching, minimal modules, secure TLS, and configuration monitoring.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3504
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During a financial-services purple-team test (FIN-PT-M13-3504), which action most directly controls the risk related to "secure web-server configuration"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Use hardened baselines, patching, minimal modules, secure TLS, and configuration monitoring.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3505
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During a cloud startup security audit (CLD-AUDIT-M13-3505), which action most directly controls the risk related to "secure web-server configuration"?

View answer choices
  1. Use hardened baselines, patching, minimal modules, secure TLS, and configuration monitoring.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3506
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During a government risk-validation project (GOV-RISK-M13-3506), which action most directly controls the risk related to "secure web-server configuration"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Use hardened baselines, patching, minimal modules, secure TLS, and configuration monitoring.
Practice
3507
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During an e-commerce application review (ECOM-WEB-M13-3507), which action most directly controls the risk related to "secure web-server configuration"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Use hardened baselines, patching, minimal modules, secure TLS, and configuration monitoring.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3508
Module 13 · Advanced Domain 3 · Security secure web-server configuration Unanswered

During a manufacturing and OT security review (MFG-OT-M13-3508), which action most directly controls the risk related to "secure web-server configuration"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Use hardened baselines, patching, minimal modules, secure TLS, and configuration monitoring.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3509
Module 13 · Advanced Domain 3 · Security secure web-server configuration Unanswered

During a mobile-services penetration test (MOB-TEST-M13-3509), which action most directly controls the risk related to "secure web-server configuration"?

View answer choices
  1. Use hardened baselines, patching, minimal modules, secure TLS, and configuration monitoring.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3510
Module 13 · Advanced Domain 3 · Security secure web-server configuration Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M13-3510), which action most directly controls the risk related to "secure web-server configuration"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Use hardened baselines, patching, minimal modules, secure TLS, and configuration monitoring.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3511
Module 13 · Foundation Domain 3 · Security secure web-server configuration Unanswered

During an authorized retail-company assessment (RET-LAB-M13-3511), which evidence best supports an assessment of "secure web-server configuration"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A configuration assessment compared against the approved hardened baseline.
Practice
3512
Module 13 · Foundation Domain 3 · Security secure web-server configuration Unanswered

During a hospital incident-response exercise (HLT-SOC-M13-3512), which evidence best supports an assessment of "secure web-server configuration"?

View answer choices
  1. A configuration assessment compared against the approved hardened baseline.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3513
Module 13 · Foundation Domain 3 · Security secure web-server configuration Unanswered

During a university cyber-range engagement (EDU-RANGE-M13-3513), which evidence best supports an assessment of "secure web-server configuration"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A configuration assessment compared against the approved hardened baseline.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3514
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During a financial-services purple-team test (FIN-PT-M13-3514), which evidence best supports an assessment of "secure web-server configuration"?

View answer choices
  1. A configuration assessment compared against the approved hardened baseline.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3515
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During a cloud startup security audit (CLD-AUDIT-M13-3515), which evidence best supports an assessment of "secure web-server configuration"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A configuration assessment compared against the approved hardened baseline.
Practice
3516
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During a government risk-validation project (GOV-RISK-M13-3516), which evidence best supports an assessment of "secure web-server configuration"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A configuration assessment compared against the approved hardened baseline.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3517
Module 13 · Applied Domain 3 · Security secure web-server configuration Unanswered

During an e-commerce application review (ECOM-WEB-M13-3517), which evidence best supports an assessment of "secure web-server configuration"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A configuration assessment compared against the approved hardened baseline.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3518
Module 13 · Advanced Domain 3 · Security secure web-server configuration Unanswered

During a manufacturing and OT security review (MFG-OT-M13-3518), which evidence best supports an assessment of "secure web-server configuration"?

View answer choices
  1. A configuration assessment compared against the approved hardened baseline.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3519
Module 13 · Advanced Domain 3 · Security secure web-server configuration Unanswered

During a mobile-services penetration test (MOB-TEST-M13-3519), which evidence best supports an assessment of "secure web-server configuration"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A configuration assessment compared against the approved hardened baseline.
Practice
3520
Module 13 · Advanced Domain 3 · Security secure web-server configuration Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M13-3520), which evidence best supports an assessment of "secure web-server configuration"?

View answer choices
  1. A configuration assessment compared against the approved hardened baseline.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3521
Module 13 · Foundation Domain 4 · Tools / Systems / Programs Nikto Unanswered

During an authorized retail-company assessment (RET-LAB-M13-3521), which statement most accurately defines "Nikto"?

View answer choices
  1. A search service that indexes Internet-connected devices and service banners.
  2. A web-server scanner that checks for known dangerous files, versions, and configuration issues.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
3522
Module 13 · Foundation Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a hospital incident-response exercise (HLT-SOC-M13-3522), which statement most accurately defines "Nikto"?

View answer choices
  1. A web-server scanner that checks for known dangerous files, versions, and configuration issues.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
3523
Module 13 · Foundation Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a university cyber-range engagement (EDU-RANGE-M13-3523), which statement most accurately defines "Nikto"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A web-server scanner that checks for known dangerous files, versions, and configuration issues.
Practice
3524
Module 13 · Applied Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a financial-services purple-team test (FIN-PT-M13-3524), which statement most accurately defines "Nikto"?

View answer choices
  1. A web-server scanner that checks for known dangerous files, versions, and configuration issues.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
3525
Module 13 · Applied Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a cloud startup security audit (CLD-AUDIT-M13-3525), which statement most accurately defines "Nikto"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A web-server scanner that checks for known dangerous files, versions, and configuration issues.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
3526
Module 13 · Applied Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a government risk-validation project (GOV-RISK-M13-3526), which statement most accurately defines "Nikto"?

View answer choices
  1. A web-server scanner that checks for known dangerous files, versions, and configuration issues.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
3527
Module 13 · Applied Domain 4 · Tools / Systems / Programs Nikto Unanswered

During an e-commerce application review (ECOM-WEB-M13-3527), which statement most accurately defines "Nikto"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A web-server scanner that checks for known dangerous files, versions, and configuration issues.
Practice
3528
Module 13 · Advanced Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a manufacturing and OT security review (MFG-OT-M13-3528), which statement most accurately defines "Nikto"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A web-server scanner that checks for known dangerous files, versions, and configuration issues.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
3529
Module 13 · Advanced Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a mobile-services penetration test (MOB-TEST-M13-3529), which statement most accurately defines "Nikto"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A web-server scanner that checks for known dangerous files, versions, and configuration issues.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
3530
Module 13 · Advanced Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M13-3530), which statement most accurately defines "Nikto"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A web-server scanner that checks for known dangerous files, versions, and configuration issues.
Practice
3531
Module 13 · Foundation Domain 4 · Tools / Systems / Programs Nikto Unanswered

During an authorized retail-company assessment (RET-LAB-M13-3531), which risk is most directly associated with "Nikto"?

View answer choices
  1. Noisy requests can trigger defenses and findings may require validation.
  2. Automated modules can query third parties or collect data outside scope.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3532
Module 13 · Foundation Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a hospital incident-response exercise (HLT-SOC-M13-3532), which risk is most directly associated with "Nikto"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Noisy requests can trigger defenses and findings may require validation.
  4. Automated modules can query third parties or collect data outside scope.
Practice
3533
Module 13 · Foundation Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a university cyber-range engagement (EDU-RANGE-M13-3533), which risk is most directly associated with "Nikto"?

View answer choices
  1. Noisy requests can trigger defenses and findings may require validation.
  2. Automated modules can query third parties or collect data outside scope.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3534
Module 13 · Applied Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a financial-services purple-team test (FIN-PT-M13-3534), which risk is most directly associated with "Nikto"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Noisy requests can trigger defenses and findings may require validation.
Practice
3535
Module 13 · Applied Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a cloud startup security audit (CLD-AUDIT-M13-3535), which risk is most directly associated with "Nikto"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Noisy requests can trigger defenses and findings may require validation.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3536
Module 13 · Applied Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a government risk-validation project (GOV-RISK-M13-3536), which risk is most directly associated with "Nikto"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Noisy requests can trigger defenses and findings may require validation.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Automated modules can query third parties or collect data outside scope.
Practice
3537
Module 13 · Applied Domain 4 · Tools / Systems / Programs Nikto Unanswered

During an e-commerce application review (ECOM-WEB-M13-3537), which risk is most directly associated with "Nikto"?

View answer choices
  1. Noisy requests can trigger defenses and findings may require validation.
  2. Automated modules can query third parties or collect data outside scope.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3538
Module 13 · Advanced Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a manufacturing and OT security review (MFG-OT-M13-3538), which risk is most directly associated with "Nikto"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Noisy requests can trigger defenses and findings may require validation.
Practice
3539
Module 13 · Advanced Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a mobile-services penetration test (MOB-TEST-M13-3539), which risk is most directly associated with "Nikto"?

View answer choices
  1. Noisy requests can trigger defenses and findings may require validation.
  2. Automated modules can query third parties or collect data outside scope.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3540
Module 13 · Advanced Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M13-3540), which risk is most directly associated with "Nikto"?

View answer choices
  1. Noisy requests can trigger defenses and findings may require validation.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3541
Module 13 · Foundation Domain 4 · Tools / Systems / Programs Nikto Unanswered

During an authorized retail-company assessment (RET-LAB-M13-3541), which action most directly controls the risk related to "Nikto"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Run only against authorized hosts and verify findings against configuration.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3542
Module 13 · Foundation Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a hospital incident-response exercise (HLT-SOC-M13-3542), which action most directly controls the risk related to "Nikto"?

View answer choices
  1. Run only against authorized hosts and verify findings against configuration.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3543
Module 13 · Foundation Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a university cyber-range engagement (EDU-RANGE-M13-3543), which action most directly controls the risk related to "Nikto"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Run only against authorized hosts and verify findings against configuration.
Practice
3544
Module 13 · Applied Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a financial-services purple-team test (FIN-PT-M13-3544), which action most directly controls the risk related to "Nikto"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Run only against authorized hosts and verify findings against configuration.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3545
Module 13 · Applied Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a cloud startup security audit (CLD-AUDIT-M13-3545), which action most directly controls the risk related to "Nikto"?

View answer choices
  1. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  2. Run only against authorized hosts and verify findings against configuration.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3546
Module 13 · Applied Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a government risk-validation project (GOV-RISK-M13-3546), which action most directly controls the risk related to "Nikto"?

View answer choices
  1. Run only against authorized hosts and verify findings against configuration.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3547
Module 13 · Applied Domain 4 · Tools / Systems / Programs Nikto Unanswered

During an e-commerce application review (ECOM-WEB-M13-3547), which action most directly controls the risk related to "Nikto"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Run only against authorized hosts and verify findings against configuration.
Practice
3548
Module 13 · Advanced Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a manufacturing and OT security review (MFG-OT-M13-3548), which action most directly controls the risk related to "Nikto"?

View answer choices
  1. Run only against authorized hosts and verify findings against configuration.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3549
Module 13 · Advanced Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a mobile-services penetration test (MOB-TEST-M13-3549), which action most directly controls the risk related to "Nikto"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Run only against authorized hosts and verify findings against configuration.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3550
Module 13 · Advanced Domain 4 · Tools / Systems / Programs Nikto Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M13-3550), which action most directly controls the risk related to "Nikto"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Run only against authorized hosts and verify findings against configuration.
Practice