CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 3,651–3,700 of 5,000 matching questions

50 per page
3651
Module 14 · Foundation Domain 3 · Security web application firewall Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3651), which risk is most directly associated with "web application firewall"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. A WAF can be bypassed and cannot correct insecure application code.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3652
Module 14 · Foundation Domain 3 · Security web application firewall Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3652), which risk is most directly associated with "web application firewall"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. A WAF can be bypassed and cannot correct insecure application code.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3653
Module 14 · Foundation Domain 3 · Security web application firewall Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3653), which risk is most directly associated with "web application firewall"?

View answer choices
  1. A WAF can be bypassed and cannot correct insecure application code.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3654
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During a financial-services purple-team test (FIN-PT-M14-3654), which risk is most directly associated with "web application firewall"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. A WAF can be bypassed and cannot correct insecure application code.
Practice
3655
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3655), which risk is most directly associated with "web application firewall"?

View answer choices
  1. A WAF can be bypassed and cannot correct insecure application code.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3656
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During a government risk-validation project (GOV-RISK-M14-3656), which risk is most directly associated with "web application firewall"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. A WAF can be bypassed and cannot correct insecure application code.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3657
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During an e-commerce application review (ECOM-WEB-M14-3657), which risk is most directly associated with "web application firewall"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. A WAF can be bypassed and cannot correct insecure application code.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
3658
Module 14 · Advanced Domain 3 · Security web application firewall Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3658), which risk is most directly associated with "web application firewall"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. A WAF can be bypassed and cannot correct insecure application code.
Practice
3659
Module 14 · Advanced Domain 3 · Security web application firewall Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3659), which risk is most directly associated with "web application firewall"?

View answer choices
  1. A WAF can be bypassed and cannot correct insecure application code.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
3660
Module 14 · Advanced Domain 3 · Security web application firewall Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3660), which risk is most directly associated with "web application firewall"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. A WAF can be bypassed and cannot correct insecure application code.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
3661
Module 14 · Foundation Domain 3 · Security web application firewall Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3661), which action most directly controls the risk related to "web application firewall"?

View answer choices
  1. Tune it as a compensating control while fixing root application vulnerabilities.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3662
Module 14 · Foundation Domain 3 · Security web application firewall Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3662), which action most directly controls the risk related to "web application firewall"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Tune it as a compensating control while fixing root application vulnerabilities.
Practice
3663
Module 14 · Foundation Domain 3 · Security web application firewall Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3663), which action most directly controls the risk related to "web application firewall"?

View answer choices
  1. Tune it as a compensating control while fixing root application vulnerabilities.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3664
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During a financial-services purple-team test (FIN-PT-M14-3664), which action most directly controls the risk related to "web application firewall"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Tune it as a compensating control while fixing root application vulnerabilities.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3665
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3665), which action most directly controls the risk related to "web application firewall"?

View answer choices
  1. Tune it as a compensating control while fixing root application vulnerabilities.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3666
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During a government risk-validation project (GOV-RISK-M14-3666), which action most directly controls the risk related to "web application firewall"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Tune it as a compensating control while fixing root application vulnerabilities.
Practice
3667
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During an e-commerce application review (ECOM-WEB-M14-3667), which action most directly controls the risk related to "web application firewall"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Tune it as a compensating control while fixing root application vulnerabilities.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3668
Module 14 · Advanced Domain 3 · Security web application firewall Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3668), which action most directly controls the risk related to "web application firewall"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Tune it as a compensating control while fixing root application vulnerabilities.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
3669
Module 14 · Advanced Domain 3 · Security web application firewall Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3669), which action most directly controls the risk related to "web application firewall"?

View answer choices
  1. Tune it as a compensating control while fixing root application vulnerabilities.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
3670
Module 14 · Advanced Domain 3 · Security web application firewall Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3670), which action most directly controls the risk related to "web application firewall"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Tune it as a compensating control while fixing root application vulnerabilities.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
3671
Module 14 · Foundation Domain 3 · Security web application firewall Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3671), which evidence best supports an assessment of "web application firewall"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A WAF event correlated with the HTTP request, rule, action, and application response.
Practice
3672
Module 14 · Foundation Domain 3 · Security web application firewall Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3672), which evidence best supports an assessment of "web application firewall"?

View answer choices
  1. A WAF event correlated with the HTTP request, rule, action, and application response.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3673
Module 14 · Foundation Domain 3 · Security web application firewall Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3673), which evidence best supports an assessment of "web application firewall"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A WAF event correlated with the HTTP request, rule, action, and application response.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3674
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During a financial-services purple-team test (FIN-PT-M14-3674), which evidence best supports an assessment of "web application firewall"?

View answer choices
  1. A WAF event correlated with the HTTP request, rule, action, and application response.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3675
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3675), which evidence best supports an assessment of "web application firewall"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A WAF event correlated with the HTTP request, rule, action, and application response.
Practice
3676
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During a government risk-validation project (GOV-RISK-M14-3676), which evidence best supports an assessment of "web application firewall"?

View answer choices
  1. A WAF event correlated with the HTTP request, rule, action, and application response.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3677
Module 14 · Applied Domain 3 · Security web application firewall Unanswered

During an e-commerce application review (ECOM-WEB-M14-3677), which evidence best supports an assessment of "web application firewall"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A WAF event correlated with the HTTP request, rule, action, and application response.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
3678
Module 14 · Advanced Domain 3 · Security web application firewall Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3678), which evidence best supports an assessment of "web application firewall"?

View answer choices
  1. A WAF event correlated with the HTTP request, rule, action, and application response.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
3679
Module 14 · Advanced Domain 3 · Security web application firewall Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3679), which evidence best supports an assessment of "web application firewall"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A WAF event correlated with the HTTP request, rule, action, and application response.
Practice
3680
Module 14 · Advanced Domain 3 · Security web application firewall Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3680), which evidence best supports an assessment of "web application firewall"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A WAF event correlated with the HTTP request, rule, action, and application response.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
3681
Module 14 · Foundation Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3681), which statement most accurately defines "Burp Suite"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A search service that indexes Internet-connected devices and service banners.
  3. An intercepting web proxy and testing platform used to inspect and modify application traffic.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
3682
Module 14 · Foundation Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3682), which statement most accurately defines "Burp Suite"?

View answer choices
  1. An intercepting web proxy and testing platform used to inspect and modify application traffic.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
3683
Module 14 · Foundation Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3683), which statement most accurately defines "Burp Suite"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. An intercepting web proxy and testing platform used to inspect and modify application traffic.
Practice
3684
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a financial-services purple-team test (FIN-PT-M14-3684), which statement most accurately defines "Burp Suite"?

View answer choices
  1. An intercepting web proxy and testing platform used to inspect and modify application traffic.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
3685
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3685), which statement most accurately defines "Burp Suite"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A search service that indexes Internet-connected devices and service banners.
  3. An intercepting web proxy and testing platform used to inspect and modify application traffic.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
3686
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a government risk-validation project (GOV-RISK-M14-3686), which statement most accurately defines "Burp Suite"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. An intercepting web proxy and testing platform used to inspect and modify application traffic.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
3687
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During an e-commerce application review (ECOM-WEB-M14-3687), which statement most accurately defines "Burp Suite"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. An intercepting web proxy and testing platform used to inspect and modify application traffic.
Practice
3688
Module 14 · Advanced Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3688), which statement most accurately defines "Burp Suite"?

View answer choices
  1. An intercepting web proxy and testing platform used to inspect and modify application traffic.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
3689
Module 14 · Advanced Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3689), which statement most accurately defines "Burp Suite"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. An intercepting web proxy and testing platform used to inspect and modify application traffic.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
3690
Module 14 · Advanced Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3690), which statement most accurately defines "Burp Suite"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. An intercepting web proxy and testing platform used to inspect and modify application traffic.
Practice
3691
Module 14 · Foundation Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3691), which risk is most directly associated with "Burp Suite"?

View answer choices
  1. Active tests can change data, trigger transactions, or affect other users.
  2. Automated modules can query third parties or collect data outside scope.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3692
Module 14 · Foundation Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3692), which risk is most directly associated with "Burp Suite"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Active tests can change data, trigger transactions, or affect other users.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Automated modules can query third parties or collect data outside scope.
Practice
3693
Module 14 · Foundation Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3693), which risk is most directly associated with "Burp Suite"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Active tests can change data, trigger transactions, or affect other users.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3694
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a financial-services purple-team test (FIN-PT-M14-3694), which risk is most directly associated with "Burp Suite"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Active tests can change data, trigger transactions, or affect other users.
Practice
3695
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3695), which risk is most directly associated with "Burp Suite"?

View answer choices
  1. Active tests can change data, trigger transactions, or affect other users.
  2. Automated modules can query third parties or collect data outside scope.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3696
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a government risk-validation project (GOV-RISK-M14-3696), which risk is most directly associated with "Burp Suite"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Active tests can change data, trigger transactions, or affect other users.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Automated modules can query third parties or collect data outside scope.
Practice
3697
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During an e-commerce application review (ECOM-WEB-M14-3697), which risk is most directly associated with "Burp Suite"?

View answer choices
  1. Active tests can change data, trigger transactions, or affect other users.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3698
Module 14 · Advanced Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3698), which risk is most directly associated with "Burp Suite"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Active tests can change data, trigger transactions, or affect other users.
Practice
3699
Module 14 · Advanced Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3699), which risk is most directly associated with "Burp Suite"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Active tests can change data, trigger transactions, or affect other users.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3700
Module 14 · Advanced Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3700), which risk is most directly associated with "Burp Suite"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Active tests can change data, trigger transactions, or affect other users.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Automated modules can query third parties or collect data outside scope.
Practice