CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 3,601–3,650 of 5,000 matching questions

50 per page
3601
Module 14 · Foundation Domain 3 · Security server-side input validation Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3601), which statement most accurately defines "server-side input validation"?

View answer choices
  1. Validation performed by the trusted application tier against expected type, length, format, and range.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3602
Module 14 · Foundation Domain 3 · Security server-side input validation Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3602), which statement most accurately defines "server-side input validation"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Validation performed by the trusted application tier against expected type, length, format, and range.
Practice
3603
Module 14 · Foundation Domain 3 · Security server-side input validation Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3603), which statement most accurately defines "server-side input validation"?

View answer choices
  1. Validation performed by the trusted application tier against expected type, length, format, and range.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3604
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During a financial-services purple-team test (FIN-PT-M14-3604), which statement most accurately defines "server-side input validation"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Validation performed by the trusted application tier against expected type, length, format, and range.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3605
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3605), which statement most accurately defines "server-side input validation"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Validation performed by the trusted application tier against expected type, length, format, and range.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3606
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During a government risk-validation project (GOV-RISK-M14-3606), which statement most accurately defines "server-side input validation"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Validation performed by the trusted application tier against expected type, length, format, and range.
Practice
3607
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During an e-commerce application review (ECOM-WEB-M14-3607), which statement most accurately defines "server-side input validation"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Validation performed by the trusted application tier against expected type, length, format, and range.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3608
Module 14 · Advanced Domain 3 · Security server-side input validation Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3608), which statement most accurately defines "server-side input validation"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Validation performed by the trusted application tier against expected type, length, format, and range.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3609
Module 14 · Advanced Domain 3 · Security server-side input validation Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3609), which statement most accurately defines "server-side input validation"?

View answer choices
  1. Validation performed by the trusted application tier against expected type, length, format, and range.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3610
Module 14 · Advanced Domain 3 · Security server-side input validation Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3610), which statement most accurately defines "server-side input validation"?

View answer choices
  1. Validation performed by the trusted application tier against expected type, length, format, and range.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3611
Module 14 · Foundation Domain 3 · Security server-side input validation Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3611), which risk is most directly associated with "server-side input validation"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Client-side checks alone can be bypassed by sending crafted requests directly.
Practice
3612
Module 14 · Foundation Domain 3 · Security server-side input validation Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3612), which risk is most directly associated with "server-side input validation"?

View answer choices
  1. Client-side checks alone can be bypassed by sending crafted requests directly.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3613
Module 14 · Foundation Domain 3 · Security server-side input validation Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3613), which risk is most directly associated with "server-side input validation"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Client-side checks alone can be bypassed by sending crafted requests directly.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3614
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During a financial-services purple-team test (FIN-PT-M14-3614), which risk is most directly associated with "server-side input validation"?

View answer choices
  1. Client-side checks alone can be bypassed by sending crafted requests directly.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3615
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3615), which risk is most directly associated with "server-side input validation"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Client-side checks alone can be bypassed by sending crafted requests directly.
Practice
3616
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During a government risk-validation project (GOV-RISK-M14-3616), which risk is most directly associated with "server-side input validation"?

View answer choices
  1. Client-side checks alone can be bypassed by sending crafted requests directly.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3617
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During an e-commerce application review (ECOM-WEB-M14-3617), which risk is most directly associated with "server-side input validation"?

View answer choices
  1. Controls chosen without risk context may protect low-value assets while critical risks remain.
  2. Client-side checks alone can be bypassed by sending crafted requests directly.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3618
Module 14 · Advanced Domain 3 · Security server-side input validation Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3618), which risk is most directly associated with "server-side input validation"?

View answer choices
  1. Client-side checks alone can be bypassed by sending crafted requests directly.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3619
Module 14 · Advanced Domain 3 · Security server-side input validation Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3619), which risk is most directly associated with "server-side input validation"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Client-side checks alone can be bypassed by sending crafted requests directly.
Practice
3620
Module 14 · Advanced Domain 3 · Security server-side input validation Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3620), which risk is most directly associated with "server-side input validation"?

View answer choices
  1. Client-side checks alone can be bypassed by sending crafted requests directly.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3621
Module 14 · Foundation Domain 3 · Security server-side input validation Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3621), which action most directly controls the risk related to "server-side input validation"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Validate on the server and encode output for its destination context.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3622
Module 14 · Foundation Domain 3 · Security server-side input validation Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3622), which action most directly controls the risk related to "server-side input validation"?

View answer choices
  1. Validate on the server and encode output for its destination context.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3623
Module 14 · Foundation Domain 3 · Security server-side input validation Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3623), which action most directly controls the risk related to "server-side input validation"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Validate on the server and encode output for its destination context.
Practice
3624
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During a financial-services purple-team test (FIN-PT-M14-3624), which action most directly controls the risk related to "server-side input validation"?

View answer choices
  1. Validate on the server and encode output for its destination context.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3625
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3625), which action most directly controls the risk related to "server-side input validation"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Validate on the server and encode output for its destination context.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3626
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During a government risk-validation project (GOV-RISK-M14-3626), which action most directly controls the risk related to "server-side input validation"?

View answer choices
  1. Validate on the server and encode output for its destination context.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3627
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During an e-commerce application review (ECOM-WEB-M14-3627), which action most directly controls the risk related to "server-side input validation"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Validate on the server and encode output for its destination context.
Practice
3628
Module 14 · Advanced Domain 3 · Security server-side input validation Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3628), which action most directly controls the risk related to "server-side input validation"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Validate on the server and encode output for its destination context.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3629
Module 14 · Advanced Domain 3 · Security server-side input validation Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3629), which action most directly controls the risk related to "server-side input validation"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Validate on the server and encode output for its destination context.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3630
Module 14 · Advanced Domain 3 · Security server-side input validation Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3630), which action most directly controls the risk related to "server-side input validation"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Validate on the server and encode output for its destination context.
Practice
3631
Module 14 · Foundation Domain 3 · Security server-side input validation Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3631), which evidence best supports an assessment of "server-side input validation"?

View answer choices
  1. A negative test showing malformed input is rejected before unsafe processing.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3632
Module 14 · Foundation Domain 3 · Security server-side input validation Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3632), which evidence best supports an assessment of "server-side input validation"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A negative test showing malformed input is rejected before unsafe processing.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3633
Module 14 · Foundation Domain 3 · Security server-side input validation Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3633), which evidence best supports an assessment of "server-side input validation"?

View answer choices
  1. A negative test showing malformed input is rejected before unsafe processing.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3634
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During a financial-services purple-team test (FIN-PT-M14-3634), which evidence best supports an assessment of "server-side input validation"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A negative test showing malformed input is rejected before unsafe processing.
Practice
3635
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3635), which evidence best supports an assessment of "server-side input validation"?

View answer choices
  1. A negative test showing malformed input is rejected before unsafe processing.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3636
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During a government risk-validation project (GOV-RISK-M14-3636), which evidence best supports an assessment of "server-side input validation"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A negative test showing malformed input is rejected before unsafe processing.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3637
Module 14 · Applied Domain 3 · Security server-side input validation Unanswered

During an e-commerce application review (ECOM-WEB-M14-3637), which evidence best supports an assessment of "server-side input validation"?

View answer choices
  1. A negative test showing malformed input is rejected before unsafe processing.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3638
Module 14 · Advanced Domain 3 · Security server-side input validation Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3638), which evidence best supports an assessment of "server-side input validation"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A negative test showing malformed input is rejected before unsafe processing.
Practice
3639
Module 14 · Advanced Domain 3 · Security server-side input validation Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3639), which evidence best supports an assessment of "server-side input validation"?

View answer choices
  1. A negative test showing malformed input is rejected before unsafe processing.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3640
Module 14 · Advanced Domain 3 · Security server-side input validation Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3640), which evidence best supports an assessment of "server-side input validation"?

View answer choices
  1. A negative test showing malformed input is rejected before unsafe processing.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3641
Module 14 · Foundation Domain 3 · Security web application firewall Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3641), which statement most accurately defines "web application firewall"?

View answer choices
  1. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  2. An application-aware control that filters HTTP traffic using rules and behavioral context.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3642
Module 14 · Foundation Domain 3 · Security web application firewall Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3642), which statement most accurately defines "web application firewall"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. An application-aware control that filters HTTP traffic using rules and behavioral context.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3643
Module 14 · Foundation Domain 3 · Security web application firewall Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3643), which statement most accurately defines "web application firewall"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. An application-aware control that filters HTTP traffic using rules and behavioral context.
Practice
3644
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During a financial-services purple-team test (FIN-PT-M14-3644), which statement most accurately defines "web application firewall"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. An application-aware control that filters HTTP traffic using rules and behavioral context.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3645
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3645), which statement most accurately defines "web application firewall"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. An application-aware control that filters HTTP traffic using rules and behavioral context.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3646
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During a government risk-validation project (GOV-RISK-M14-3646), which statement most accurately defines "web application firewall"?

View answer choices
  1. An application-aware control that filters HTTP traffic using rules and behavioral context.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
3647
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During an e-commerce application review (ECOM-WEB-M14-3647), which statement most accurately defines "web application firewall"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. An application-aware control that filters HTTP traffic using rules and behavioral context.
Practice
3648
Module 14 · Advanced Domain 3 · Security web application firewall Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3648), which statement most accurately defines "web application firewall"?

View answer choices
  1. An application-aware control that filters HTTP traffic using rules and behavioral context.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
3649
Module 14 · Advanced Domain 3 · Security web application firewall Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3649), which statement most accurately defines "web application firewall"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. An application-aware control that filters HTTP traffic using rules and behavioral context.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
3650
Module 14 · Advanced Domain 3 · Security web application firewall Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3650), which statement most accurately defines "web application firewall"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. An application-aware control that filters HTTP traffic using rules and behavioral context.
Practice