CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 4,051–4,100 of 5,000 matching questions

50 per page
4051
Module 16 · Foundation Domain 3 · Security rogue access-point detection Unanswered

During an authorized retail-company assessment (RET-LAB-M16-4051), which risk is most directly associated with "rogue access-point detection"?

View answer choices
  1. Rogue or evil-twin APs can capture credentials or bridge around network controls.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
4052
Module 16 · Foundation Domain 3 · Security rogue access-point detection Unanswered

During a hospital incident-response exercise (HLT-SOC-M16-4052), which risk is most directly associated with "rogue access-point detection"?

View answer choices
  1. Controls chosen without risk context may protect low-value assets while critical risks remain.
  2. Rogue or evil-twin APs can capture credentials or bridge around network controls.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
4053
Module 16 · Foundation Domain 3 · Security rogue access-point detection Unanswered

During a university cyber-range engagement (EDU-RANGE-M16-4053), which risk is most directly associated with "rogue access-point detection"?

View answer choices
  1. Rogue or evil-twin APs can capture credentials or bridge around network controls.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
4054
Module 16 · Applied Domain 3 · Security rogue access-point detection Unanswered

During a financial-services purple-team test (FIN-PT-M16-4054), which risk is most directly associated with "rogue access-point detection"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Rogue or evil-twin APs can capture credentials or bridge around network controls.
Practice
4055
Module 16 · Applied Domain 3 · Security rogue access-point detection Unanswered

During a cloud startup security audit (CLD-AUDIT-M16-4055), which risk is most directly associated with "rogue access-point detection"?

View answer choices
  1. Rogue or evil-twin APs can capture credentials or bridge around network controls.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
4056
Module 16 · Applied Domain 3 · Security rogue access-point detection Unanswered

During a government risk-validation project (GOV-RISK-M16-4056), which risk is most directly associated with "rogue access-point detection"?

View answer choices
  1. Controls chosen without risk context may protect low-value assets while critical risks remain.
  2. Rogue or evil-twin APs can capture credentials or bridge around network controls.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
4057
Module 16 · Applied Domain 3 · Security rogue access-point detection Unanswered

During an e-commerce application review (ECOM-WEB-M16-4057), which risk is most directly associated with "rogue access-point detection"?

View answer choices
  1. Rogue or evil-twin APs can capture credentials or bridge around network controls.
  2. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
4058
Module 16 · Advanced Domain 3 · Security rogue access-point detection Unanswered

During a manufacturing and OT security review (MFG-OT-M16-4058), which risk is most directly associated with "rogue access-point detection"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Rogue or evil-twin APs can capture credentials or bridge around network controls.
Practice
4059
Module 16 · Advanced Domain 3 · Security rogue access-point detection Unanswered

During a mobile-services penetration test (MOB-TEST-M16-4059), which risk is most directly associated with "rogue access-point detection"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Rogue or evil-twin APs can capture credentials or bridge around network controls.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
4060
Module 16 · Advanced Domain 3 · Security rogue access-point detection Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M16-4060), which risk is most directly associated with "rogue access-point detection"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Rogue or evil-twin APs can capture credentials or bridge around network controls.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
4061
Module 16 · Foundation Domain 3 · Security rogue access-point detection Unanswered

During an authorized retail-company assessment (RET-LAB-M16-4061), which action most directly controls the risk related to "rogue access-point detection"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Use wireless monitoring, approved inventories, location analysis, and rapid containment procedures.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
4062
Module 16 · Foundation Domain 3 · Security rogue access-point detection Unanswered

During a hospital incident-response exercise (HLT-SOC-M16-4062), which action most directly controls the risk related to "rogue access-point detection"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Use wireless monitoring, approved inventories, location analysis, and rapid containment procedures.
Practice
4063
Module 16 · Foundation Domain 3 · Security rogue access-point detection Unanswered

During a university cyber-range engagement (EDU-RANGE-M16-4063), which action most directly controls the risk related to "rogue access-point detection"?

View answer choices
  1. Use wireless monitoring, approved inventories, location analysis, and rapid containment procedures.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
4064
Module 16 · Applied Domain 3 · Security rogue access-point detection Unanswered

During a financial-services purple-team test (FIN-PT-M16-4064), which action most directly controls the risk related to "rogue access-point detection"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Use wireless monitoring, approved inventories, location analysis, and rapid containment procedures.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
4065
Module 16 · Applied Domain 3 · Security rogue access-point detection Unanswered

During a cloud startup security audit (CLD-AUDIT-M16-4065), which action most directly controls the risk related to "rogue access-point detection"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Use wireless monitoring, approved inventories, location analysis, and rapid containment procedures.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
4066
Module 16 · Applied Domain 3 · Security rogue access-point detection Unanswered

During a government risk-validation project (GOV-RISK-M16-4066), which action most directly controls the risk related to "rogue access-point detection"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Use wireless monitoring, approved inventories, location analysis, and rapid containment procedures.
Practice
4067
Module 16 · Applied Domain 3 · Security rogue access-point detection Unanswered

During an e-commerce application review (ECOM-WEB-M16-4067), which action most directly controls the risk related to "rogue access-point detection"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Use wireless monitoring, approved inventories, location analysis, and rapid containment procedures.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
4068
Module 16 · Advanced Domain 3 · Security rogue access-point detection Unanswered

During a manufacturing and OT security review (MFG-OT-M16-4068), which action most directly controls the risk related to "rogue access-point detection"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Use wireless monitoring, approved inventories, location analysis, and rapid containment procedures.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
4069
Module 16 · Advanced Domain 3 · Security rogue access-point detection Unanswered

During a mobile-services penetration test (MOB-TEST-M16-4069), which action most directly controls the risk related to "rogue access-point detection"?

View answer choices
  1. Use wireless monitoring, approved inventories, location analysis, and rapid containment procedures.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
4070
Module 16 · Advanced Domain 3 · Security rogue access-point detection Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M16-4070), which action most directly controls the risk related to "rogue access-point detection"?

View answer choices
  1. Use wireless monitoring, approved inventories, location analysis, and rapid containment procedures.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
4071
Module 16 · Foundation Domain 3 · Security rogue access-point detection Unanswered

During an authorized retail-company assessment (RET-LAB-M16-4071), which evidence best supports an assessment of "rogue access-point detection"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. RF observations correlating BSSID, SSID, channel, location, and wired-network presence.
Practice
4072
Module 16 · Foundation Domain 3 · Security rogue access-point detection Unanswered

During a hospital incident-response exercise (HLT-SOC-M16-4072), which evidence best supports an assessment of "rogue access-point detection"?

View answer choices
  1. RF observations correlating BSSID, SSID, channel, location, and wired-network presence.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
4073
Module 16 · Foundation Domain 3 · Security rogue access-point detection Unanswered

During a university cyber-range engagement (EDU-RANGE-M16-4073), which evidence best supports an assessment of "rogue access-point detection"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. RF observations correlating BSSID, SSID, channel, location, and wired-network presence.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
4074
Module 16 · Applied Domain 3 · Security rogue access-point detection Unanswered

During a financial-services purple-team test (FIN-PT-M16-4074), which evidence best supports an assessment of "rogue access-point detection"?

View answer choices
  1. RF observations correlating BSSID, SSID, channel, location, and wired-network presence.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
4075
Module 16 · Applied Domain 3 · Security rogue access-point detection Unanswered

During a cloud startup security audit (CLD-AUDIT-M16-4075), which evidence best supports an assessment of "rogue access-point detection"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. RF observations correlating BSSID, SSID, channel, location, and wired-network presence.
Practice
4076
Module 16 · Applied Domain 3 · Security rogue access-point detection Unanswered

During a government risk-validation project (GOV-RISK-M16-4076), which evidence best supports an assessment of "rogue access-point detection"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. RF observations correlating BSSID, SSID, channel, location, and wired-network presence.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
4077
Module 16 · Applied Domain 3 · Security rogue access-point detection Unanswered

During an e-commerce application review (ECOM-WEB-M16-4077), which evidence best supports an assessment of "rogue access-point detection"?

View answer choices
  1. A risk register with likelihood, impact, owner, treatment, and review date.
  2. RF observations correlating BSSID, SSID, channel, location, and wired-network presence.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
4078
Module 16 · Advanced Domain 3 · Security rogue access-point detection Unanswered

During a manufacturing and OT security review (MFG-OT-M16-4078), which evidence best supports an assessment of "rogue access-point detection"?

View answer choices
  1. RF observations correlating BSSID, SSID, channel, location, and wired-network presence.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
4079
Module 16 · Advanced Domain 3 · Security rogue access-point detection Unanswered

During a mobile-services penetration test (MOB-TEST-M16-4079), which evidence best supports an assessment of "rogue access-point detection"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. RF observations correlating BSSID, SSID, channel, location, and wired-network presence.
Practice
4080
Module 16 · Advanced Domain 3 · Security rogue access-point detection Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M16-4080), which evidence best supports an assessment of "rogue access-point detection"?

View answer choices
  1. RF observations correlating BSSID, SSID, channel, location, and wired-network presence.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
4081
Module 16 · Foundation Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During an authorized retail-company assessment (RET-LAB-M16-4081), which statement most accurately defines "Aircrack-ng"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A suite for authorized wireless capture, analysis, and key-security assessment.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
4082
Module 16 · Foundation Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a hospital incident-response exercise (HLT-SOC-M16-4082), which statement most accurately defines "Aircrack-ng"?

View answer choices
  1. A suite for authorized wireless capture, analysis, and key-security assessment.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
4083
Module 16 · Foundation Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a university cyber-range engagement (EDU-RANGE-M16-4083), which statement most accurately defines "Aircrack-ng"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A suite for authorized wireless capture, analysis, and key-security assessment.
Practice
4084
Module 16 · Applied Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a financial-services purple-team test (FIN-PT-M16-4084), which statement most accurately defines "Aircrack-ng"?

View answer choices
  1. A suite for authorized wireless capture, analysis, and key-security assessment.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
4085
Module 16 · Applied Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a cloud startup security audit (CLD-AUDIT-M16-4085), which statement most accurately defines "Aircrack-ng"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A suite for authorized wireless capture, analysis, and key-security assessment.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
4086
Module 16 · Applied Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a government risk-validation project (GOV-RISK-M16-4086), which statement most accurately defines "Aircrack-ng"?

View answer choices
  1. A suite for authorized wireless capture, analysis, and key-security assessment.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
4087
Module 16 · Applied Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During an e-commerce application review (ECOM-WEB-M16-4087), which statement most accurately defines "Aircrack-ng"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A suite for authorized wireless capture, analysis, and key-security assessment.
Practice
4088
Module 16 · Advanced Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a manufacturing and OT security review (MFG-OT-M16-4088), which statement most accurately defines "Aircrack-ng"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A suite for authorized wireless capture, analysis, and key-security assessment.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
4089
Module 16 · Advanced Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a mobile-services penetration test (MOB-TEST-M16-4089), which statement most accurately defines "Aircrack-ng"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A suite for authorized wireless capture, analysis, and key-security assessment.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
4090
Module 16 · Advanced Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M16-4090), which statement most accurately defines "Aircrack-ng"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A suite for authorized wireless capture, analysis, and key-security assessment.
Practice
4091
Module 16 · Foundation Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During an authorized retail-company assessment (RET-LAB-M16-4091), which risk is most directly associated with "Aircrack-ng"?

View answer choices
  1. Captured handshakes can enable offline testing of weak shared credentials.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Automated modules can query third parties or collect data outside scope.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
4092
Module 16 · Foundation Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a hospital incident-response exercise (HLT-SOC-M16-4092), which risk is most directly associated with "Aircrack-ng"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Captured handshakes can enable offline testing of weak shared credentials.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Automated modules can query third parties or collect data outside scope.
Practice
4093
Module 16 · Foundation Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a university cyber-range engagement (EDU-RANGE-M16-4093), which risk is most directly associated with "Aircrack-ng"?

View answer choices
  1. Captured handshakes can enable offline testing of weak shared credentials.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
4094
Module 16 · Applied Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a financial-services purple-team test (FIN-PT-M16-4094), which risk is most directly associated with "Aircrack-ng"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Captured handshakes can enable offline testing of weak shared credentials.
Practice
4095
Module 16 · Applied Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a cloud startup security audit (CLD-AUDIT-M16-4095), which risk is most directly associated with "Aircrack-ng"?

View answer choices
  1. Captured handshakes can enable offline testing of weak shared credentials.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Automated modules can query third parties or collect data outside scope.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
4096
Module 16 · Applied Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a government risk-validation project (GOV-RISK-M16-4096), which risk is most directly associated with "Aircrack-ng"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Captured handshakes can enable offline testing of weak shared credentials.
  4. Automated modules can query third parties or collect data outside scope.
Practice
4097
Module 16 · Applied Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During an e-commerce application review (ECOM-WEB-M16-4097), which risk is most directly associated with "Aircrack-ng"?

View answer choices
  1. Captured handshakes can enable offline testing of weak shared credentials.
  2. Automated modules can query third parties or collect data outside scope.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
4098
Module 16 · Advanced Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a manufacturing and OT security review (MFG-OT-M16-4098), which risk is most directly associated with "Aircrack-ng"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Captured handshakes can enable offline testing of weak shared credentials.
Practice
4099
Module 16 · Advanced Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a mobile-services penetration test (MOB-TEST-M16-4099), which risk is most directly associated with "Aircrack-ng"?

View answer choices
  1. Captured handshakes can enable offline testing of weak shared credentials.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Automated modules can query third parties or collect data outside scope.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
4100
Module 16 · Advanced Domain 4 · Tools / Systems / Programs Aircrack-ng Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M16-4100), which risk is most directly associated with "Aircrack-ng"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Captured handshakes can enable offline testing of weak shared credentials.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Automated modules can query third parties or collect data outside scope.
Practice