CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 3,701–3,750 of 5,000 matching questions

50 per page
3701
Module 14 · Foundation Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3701), which action most directly controls the risk related to "Burp Suite"?

View answer choices
  1. Use a dedicated test account, target scope, backups, and controlled active testing.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3702
Module 14 · Foundation Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3702), which action most directly controls the risk related to "Burp Suite"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Use a dedicated test account, target scope, backups, and controlled active testing.
Practice
3703
Module 14 · Foundation Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3703), which action most directly controls the risk related to "Burp Suite"?

View answer choices
  1. Use a dedicated test account, target scope, backups, and controlled active testing.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3704
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a financial-services purple-team test (FIN-PT-M14-3704), which action most directly controls the risk related to "Burp Suite"?

View answer choices
  1. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  2. Use a dedicated test account, target scope, backups, and controlled active testing.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3705
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3705), which action most directly controls the risk related to "Burp Suite"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Use a dedicated test account, target scope, backups, and controlled active testing.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3706
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a government risk-validation project (GOV-RISK-M14-3706), which action most directly controls the risk related to "Burp Suite"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Use a dedicated test account, target scope, backups, and controlled active testing.
Practice
3707
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During an e-commerce application review (ECOM-WEB-M14-3707), which action most directly controls the risk related to "Burp Suite"?

View answer choices
  1. Use a dedicated test account, target scope, backups, and controlled active testing.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3708
Module 14 · Advanced Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3708), which action most directly controls the risk related to "Burp Suite"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Use a dedicated test account, target scope, backups, and controlled active testing.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3709
Module 14 · Advanced Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3709), which action most directly controls the risk related to "Burp Suite"?

View answer choices
  1. Use a dedicated test account, target scope, backups, and controlled active testing.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3710
Module 14 · Advanced Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3710), which action most directly controls the risk related to "Burp Suite"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Use a dedicated test account, target scope, backups, and controlled active testing.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3711
Module 14 · Foundation Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3711), which evidence best supports an assessment of "Burp Suite"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Saved requests and responses showing the verified application weakness.
Practice
3712
Module 14 · Foundation Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3712), which evidence best supports an assessment of "Burp Suite"?

View answer choices
  1. Saved requests and responses showing the verified application weakness.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A relationship graph retaining sources and transformation history.
Practice
3713
Module 14 · Foundation Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3713), which evidence best supports an assessment of "Burp Suite"?

View answer choices
  1. Search results validated against the organization’s current external inventory.
  2. Saved requests and responses showing the verified application weakness.
  3. A relationship graph retaining sources and transformation history.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
3714
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a financial-services purple-team test (FIN-PT-M14-3714), which evidence best supports an assessment of "Burp Suite"?

View answer choices
  1. Saved requests and responses showing the verified application weakness.
  2. A relationship graph retaining sources and transformation history.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Search results validated against the organization’s current external inventory.
Practice
3715
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3715), which evidence best supports an assessment of "Burp Suite"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. Search results validated against the organization’s current external inventory.
  3. A relationship graph retaining sources and transformation history.
  4. Saved requests and responses showing the verified application weakness.
Practice
3716
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a government risk-validation project (GOV-RISK-M14-3716), which evidence best supports an assessment of "Burp Suite"?

View answer choices
  1. Saved requests and responses showing the verified application weakness.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A relationship graph retaining sources and transformation history.
Practice
3717
Module 14 · Applied Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During an e-commerce application review (ECOM-WEB-M14-3717), which evidence best supports an assessment of "Burp Suite"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. Saved requests and responses showing the verified application weakness.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
3718
Module 14 · Advanced Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3718), which evidence best supports an assessment of "Burp Suite"?

View answer choices
  1. Saved requests and responses showing the verified application weakness.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. A relationship graph retaining sources and transformation history.
  4. Search results validated against the organization’s current external inventory.
Practice
3719
Module 14 · Advanced Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3719), which evidence best supports an assessment of "Burp Suite"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. Search results validated against the organization’s current external inventory.
  4. Saved requests and responses showing the verified application weakness.
Practice
3720
Module 14 · Advanced Domain 4 · Tools / Systems / Programs Burp Suite Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3720), which evidence best supports an assessment of "Burp Suite"?

View answer choices
  1. Saved requests and responses showing the verified application weakness.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. Search results validated against the organization’s current external inventory.
  4. A relationship graph retaining sources and transformation history.
Practice
3721
Module 14 · Foundation Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3721), which statement most accurately defines "OWASP ZAP"?

View answer choices
  1. A search service that indexes Internet-connected devices and service banners.
  2. A web application testing proxy and scanner supporting passive and active analysis.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
3722
Module 14 · Foundation Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3722), which statement most accurately defines "OWASP ZAP"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A web application testing proxy and scanner supporting passive and active analysis.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
3723
Module 14 · Foundation Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3723), which statement most accurately defines "OWASP ZAP"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A web application testing proxy and scanner supporting passive and active analysis.
Practice
3724
Module 14 · Applied Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a financial-services purple-team test (FIN-PT-M14-3724), which statement most accurately defines "OWASP ZAP"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A web application testing proxy and scanner supporting passive and active analysis.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
3725
Module 14 · Applied Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3725), which statement most accurately defines "OWASP ZAP"?

View answer choices
  1. A search service that indexes Internet-connected devices and service banners.
  2. A web application testing proxy and scanner supporting passive and active analysis.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
3726
Module 14 · Applied Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a government risk-validation project (GOV-RISK-M14-3726), which statement most accurately defines "OWASP ZAP"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A web application testing proxy and scanner supporting passive and active analysis.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
3727
Module 14 · Applied Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During an e-commerce application review (ECOM-WEB-M14-3727), which statement most accurately defines "OWASP ZAP"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A web application testing proxy and scanner supporting passive and active analysis.
Practice
3728
Module 14 · Advanced Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3728), which statement most accurately defines "OWASP ZAP"?

View answer choices
  1. A web application testing proxy and scanner supporting passive and active analysis.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
3729
Module 14 · Advanced Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3729), which statement most accurately defines "OWASP ZAP"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A web application testing proxy and scanner supporting passive and active analysis.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
3730
Module 14 · Advanced Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3730), which statement most accurately defines "OWASP ZAP"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A web application testing proxy and scanner supporting passive and active analysis.
Practice
3731
Module 14 · Foundation Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3731), which risk is most directly associated with "OWASP ZAP"?

View answer choices
  1. Automated active scans can submit forms or stress application endpoints.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Automated modules can query third parties or collect data outside scope.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3732
Module 14 · Foundation Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3732), which risk is most directly associated with "OWASP ZAP"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Automated active scans can submit forms or stress application endpoints.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Automated modules can query third parties or collect data outside scope.
Practice
3733
Module 14 · Foundation Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3733), which risk is most directly associated with "OWASP ZAP"?

View answer choices
  1. Automated active scans can submit forms or stress application endpoints.
  2. Automated modules can query third parties or collect data outside scope.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3734
Module 14 · Applied Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a financial-services purple-team test (FIN-PT-M14-3734), which risk is most directly associated with "OWASP ZAP"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Automated active scans can submit forms or stress application endpoints.
Practice
3735
Module 14 · Applied Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3735), which risk is most directly associated with "OWASP ZAP"?

View answer choices
  1. Automated active scans can submit forms or stress application endpoints.
  2. Automated modules can query third parties or collect data outside scope.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3736
Module 14 · Applied Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a government risk-validation project (GOV-RISK-M14-3736), which risk is most directly associated with "OWASP ZAP"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Automated active scans can submit forms or stress application endpoints.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Automated modules can query third parties or collect data outside scope.
Practice
3737
Module 14 · Applied Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During an e-commerce application review (ECOM-WEB-M14-3737), which risk is most directly associated with "OWASP ZAP"?

View answer choices
  1. Automated active scans can submit forms or stress application endpoints.
  2. Automated modules can query third parties or collect data outside scope.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3738
Module 14 · Advanced Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3738), which risk is most directly associated with "OWASP ZAP"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Automated modules can query third parties or collect data outside scope.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Automated active scans can submit forms or stress application endpoints.
Practice
3739
Module 14 · Advanced Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3739), which risk is most directly associated with "OWASP ZAP"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Automated active scans can submit forms or stress application endpoints.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3740
Module 14 · Advanced Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3740), which risk is most directly associated with "OWASP ZAP"?

View answer choices
  1. Automated active scans can submit forms or stress application endpoints.
  2. Automated modules can query third parties or collect data outside scope.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3741
Module 14 · Foundation Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During an authorized retail-company assessment (RET-LAB-M14-3741), which action most directly controls the risk related to "OWASP ZAP"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Define context, authentication, exclusions, and safe scanning policy.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3742
Module 14 · Foundation Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a hospital incident-response exercise (HLT-SOC-M14-3742), which action most directly controls the risk related to "OWASP ZAP"?

View answer choices
  1. Define context, authentication, exclusions, and safe scanning policy.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3743
Module 14 · Foundation Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a university cyber-range engagement (EDU-RANGE-M14-3743), which action most directly controls the risk related to "OWASP ZAP"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Define context, authentication, exclusions, and safe scanning policy.
Practice
3744
Module 14 · Applied Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a financial-services purple-team test (FIN-PT-M14-3744), which action most directly controls the risk related to "OWASP ZAP"?

View answer choices
  1. Define context, authentication, exclusions, and safe scanning policy.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3745
Module 14 · Applied Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a cloud startup security audit (CLD-AUDIT-M14-3745), which action most directly controls the risk related to "OWASP ZAP"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Define context, authentication, exclusions, and safe scanning policy.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3746
Module 14 · Applied Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a government risk-validation project (GOV-RISK-M14-3746), which action most directly controls the risk related to "OWASP ZAP"?

View answer choices
  1. Define context, authentication, exclusions, and safe scanning policy.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3747
Module 14 · Applied Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During an e-commerce application review (ECOM-WEB-M14-3747), which action most directly controls the risk related to "OWASP ZAP"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Define context, authentication, exclusions, and safe scanning policy.
Practice
3748
Module 14 · Advanced Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a manufacturing and OT security review (MFG-OT-M14-3748), which action most directly controls the risk related to "OWASP ZAP"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Define context, authentication, exclusions, and safe scanning policy.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3749
Module 14 · Advanced Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a mobile-services penetration test (MOB-TEST-M14-3749), which action most directly controls the risk related to "OWASP ZAP"?

View answer choices
  1. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  2. Define context, authentication, exclusions, and safe scanning policy.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3750
Module 14 · Advanced Domain 4 · Tools / Systems / Programs OWASP ZAP Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M14-3750), which action most directly controls the risk related to "OWASP ZAP"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Define context, authentication, exclusions, and safe scanning policy.
Practice