CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 4,351–4,400 of 5,000 matching questions

50 per page
4351
Module 18 · Foundation Domain 1 · Background IoT threat Unanswered

During an authorized retail-company assessment (RET-LAB-M18-4351), which evidence best supports an assessment of "IoT threat"?

View answer choices
  1. Device inventory and traffic baselines revealing exposed services or anomalous behavior.
  2. A risk register linking assets to CIA impact ratings.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
4352
Module 18 · Foundation Domain 1 · Background IoT threat Unanswered

During a hospital incident-response exercise (HLT-SOC-M18-4352), which evidence best supports an assessment of "IoT threat"?

View answer choices
  1. A detection matrix showing covered and uncovered ATT&CK techniques.
  2. Device inventory and traffic baselines revealing exposed services or anomalous behavior.
  3. A risk register linking assets to CIA impact ratings.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
4353
Module 18 · Foundation Domain 1 · Background IoT threat Unanswered

During a university cyber-range engagement (EDU-RANGE-M18-4353), which evidence best supports an assessment of "IoT threat"?

View answer choices
  1. Device inventory and traffic baselines revealing exposed services or anomalous behavior.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A risk register linking assets to CIA impact ratings.
Practice
4354
Module 18 · Applied Domain 1 · Background IoT threat Unanswered

During a financial-services purple-team test (FIN-PT-M18-4354), which evidence best supports an assessment of "IoT threat"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. A risk register linking assets to CIA impact ratings.
  4. Device inventory and traffic baselines revealing exposed services or anomalous behavior.
Practice
4355
Module 18 · Applied Domain 1 · Background IoT threat Unanswered

During a cloud startup security audit (CLD-AUDIT-M18-4355), which evidence best supports an assessment of "IoT threat"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A risk register linking assets to CIA impact ratings.
  3. Device inventory and traffic baselines revealing exposed services or anomalous behavior.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
4356
Module 18 · Applied Domain 1 · Background IoT threat Unanswered

During a government risk-validation project (GOV-RISK-M18-4356), which evidence best supports an assessment of "IoT threat"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Device inventory and traffic baselines revealing exposed services or anomalous behavior.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
4357
Module 18 · Applied Domain 1 · Background IoT threat Unanswered

During an e-commerce application review (ECOM-WEB-M18-4357), which evidence best supports an assessment of "IoT threat"?

View answer choices
  1. Device inventory and traffic baselines revealing exposed services or anomalous behavior.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. A risk register linking assets to CIA impact ratings.
Practice
4358
Module 18 · Advanced Domain 1 · Background IoT threat Unanswered

During a manufacturing and OT security review (MFG-OT-M18-4358), which evidence best supports an assessment of "IoT threat"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. Device inventory and traffic baselines revealing exposed services or anomalous behavior.
Practice
4359
Module 18 · Advanced Domain 1 · Background IoT threat Unanswered

During a mobile-services penetration test (MOB-TEST-M18-4359), which evidence best supports an assessment of "IoT threat"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A risk register linking assets to CIA impact ratings.
  3. Device inventory and traffic baselines revealing exposed services or anomalous behavior.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
4360
Module 18 · Advanced Domain 1 · Background IoT threat Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M18-4360), which evidence best supports an assessment of "IoT threat"?

View answer choices
  1. A detection matrix showing covered and uncovered ATT&CK techniques.
  2. Device inventory and traffic baselines revealing exposed services or anomalous behavior.
  3. A risk register linking assets to CIA impact ratings.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
4361
Module 18 · Foundation Domain 1 · Background OT threat Unanswered

During an authorized retail-company assessment (RET-LAB-M18-4361), which statement most accurately defines "OT threat"?

View answer choices
  1. A cyber threat capable of affecting industrial control, physical processes, or operational safety.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
4362
Module 18 · Foundation Domain 1 · Background OT threat Unanswered

During a hospital incident-response exercise (HLT-SOC-M18-4362), which statement most accurately defines "OT threat"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. A cyber threat capable of affecting industrial control, physical processes, or operational safety.
Practice
4363
Module 18 · Foundation Domain 1 · Background OT threat Unanswered

During a university cyber-range engagement (EDU-RANGE-M18-4363), which statement most accurately defines "OT threat"?

View answer choices
  1. A cyber threat capable of affecting industrial control, physical processes, or operational safety.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
4364
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During a financial-services purple-team test (FIN-PT-M18-4364), which statement most accurately defines "OT threat"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A cyber threat capable of affecting industrial control, physical processes, or operational safety.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
4365
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During a cloud startup security audit (CLD-AUDIT-M18-4365), which statement most accurately defines "OT threat"?

View answer choices
  1. A cyber threat capable of affecting industrial control, physical processes, or operational safety.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
4366
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During a government risk-validation project (GOV-RISK-M18-4366), which statement most accurately defines "OT threat"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. A cyber threat capable of affecting industrial control, physical processes, or operational safety.
Practice
4367
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During an e-commerce application review (ECOM-WEB-M18-4367), which statement most accurately defines "OT threat"?

View answer choices
  1. A cyber threat capable of affecting industrial control, physical processes, or operational safety.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
4368
Module 18 · Advanced Domain 1 · Background OT threat Unanswered

During a manufacturing and OT security review (MFG-OT-M18-4368), which statement most accurately defines "OT threat"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A cyber threat capable of affecting industrial control, physical processes, or operational safety.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
4369
Module 18 · Advanced Domain 1 · Background OT threat Unanswered

During a mobile-services penetration test (MOB-TEST-M18-4369), which statement most accurately defines "OT threat"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A cyber threat capable of affecting industrial control, physical processes, or operational safety.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
4370
Module 18 · Advanced Domain 1 · Background OT threat Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M18-4370), which statement most accurately defines "OT threat"?

View answer choices
  1. A cyber threat capable of affecting industrial control, physical processes, or operational safety.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
4371
Module 18 · Foundation Domain 1 · Background OT threat Unanswered

During an authorized retail-company assessment (RET-LAB-M18-4371), which risk is most directly associated with "OT threat"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Disruption or unsafe commands can cause physical damage and safety consequences.
Practice
4372
Module 18 · Foundation Domain 1 · Background OT threat Unanswered

During a hospital incident-response exercise (HLT-SOC-M18-4372), which risk is most directly associated with "OT threat"?

View answer choices
  1. Disruption or unsafe commands can cause physical damage and safety consequences.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
4373
Module 18 · Foundation Domain 1 · Background OT threat Unanswered

During a university cyber-range engagement (EDU-RANGE-M18-4373), which risk is most directly associated with "OT threat"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Disruption or unsafe commands can cause physical damage and safety consequences.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
4374
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During a financial-services purple-team test (FIN-PT-M18-4374), which risk is most directly associated with "OT threat"?

View answer choices
  1. Disruption or unsafe commands can cause physical damage and safety consequences.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
4375
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During a cloud startup security audit (CLD-AUDIT-M18-4375), which risk is most directly associated with "OT threat"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Disruption or unsafe commands can cause physical damage and safety consequences.
Practice
4376
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During a government risk-validation project (GOV-RISK-M18-4376), which risk is most directly associated with "OT threat"?

View answer choices
  1. Disruption or unsafe commands can cause physical damage and safety consequences.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
4377
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During an e-commerce application review (ECOM-WEB-M18-4377), which risk is most directly associated with "OT threat"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Disruption or unsafe commands can cause physical damage and safety consequences.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
4378
Module 18 · Advanced Domain 1 · Background OT threat Unanswered

During a manufacturing and OT security review (MFG-OT-M18-4378), which risk is most directly associated with "OT threat"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. A control focused on only one objective can leave the other security objectives exposed.
  3. Disruption or unsafe commands can cause physical damage and safety consequences.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
4379
Module 18 · Advanced Domain 1 · Background OT threat Unanswered

During a mobile-services penetration test (MOB-TEST-M18-4379), which risk is most directly associated with "OT threat"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Disruption or unsafe commands can cause physical damage and safety consequences.
Practice
4380
Module 18 · Advanced Domain 1 · Background OT threat Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M18-4380), which risk is most directly associated with "OT threat"?

View answer choices
  1. Disruption or unsafe commands can cause physical damage and safety consequences.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
4381
Module 18 · Foundation Domain 1 · Background OT threat Unanswered

During an authorized retail-company assessment (RET-LAB-M18-4381), which action most directly controls the risk related to "OT threat"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Prioritize safety, segmentation, allowlisting, monitoring, and controlled change management.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
4382
Module 18 · Foundation Domain 1 · Background OT threat Unanswered

During a hospital incident-response exercise (HLT-SOC-M18-4382), which action most directly controls the risk related to "OT threat"?

View answer choices
  1. Prioritize safety, segmentation, allowlisting, monitoring, and controlled change management.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
4383
Module 18 · Foundation Domain 1 · Background OT threat Unanswered

During a university cyber-range engagement (EDU-RANGE-M18-4383), which action most directly controls the risk related to "OT threat"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Prioritize safety, segmentation, allowlisting, monitoring, and controlled change management.
Practice
4384
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During a financial-services purple-team test (FIN-PT-M18-4384), which action most directly controls the risk related to "OT threat"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Prioritize safety, segmentation, allowlisting, monitoring, and controlled change management.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
4385
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During a cloud startup security audit (CLD-AUDIT-M18-4385), which action most directly controls the risk related to "OT threat"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Prioritize safety, segmentation, allowlisting, monitoring, and controlled change management.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
4386
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During a government risk-validation project (GOV-RISK-M18-4386), which action most directly controls the risk related to "OT threat"?

View answer choices
  1. Prioritize safety, segmentation, allowlisting, monitoring, and controlled change management.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
4387
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During an e-commerce application review (ECOM-WEB-M18-4387), which action most directly controls the risk related to "OT threat"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Prioritize safety, segmentation, allowlisting, monitoring, and controlled change management.
Practice
4388
Module 18 · Advanced Domain 1 · Background OT threat Unanswered

During a manufacturing and OT security review (MFG-OT-M18-4388), which action most directly controls the risk related to "OT threat"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Prioritize safety, segmentation, allowlisting, monitoring, and controlled change management.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
4389
Module 18 · Advanced Domain 1 · Background OT threat Unanswered

During a mobile-services penetration test (MOB-TEST-M18-4389), which action most directly controls the risk related to "OT threat"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Prioritize safety, segmentation, allowlisting, monitoring, and controlled change management.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
4390
Module 18 · Advanced Domain 1 · Background OT threat Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M18-4390), which action most directly controls the risk related to "OT threat"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Prioritize safety, segmentation, allowlisting, monitoring, and controlled change management.
Practice
4391
Module 18 · Foundation Domain 1 · Background OT threat Unanswered

During an authorized retail-company assessment (RET-LAB-M18-4391), which evidence best supports an assessment of "OT threat"?

View answer choices
  1. Process-aware telemetry correlating network commands with physical-state changes.
  2. A risk register linking assets to CIA impact ratings.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
4392
Module 18 · Foundation Domain 1 · Background OT threat Unanswered

During a hospital incident-response exercise (HLT-SOC-M18-4392), which evidence best supports an assessment of "OT threat"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Process-aware telemetry correlating network commands with physical-state changes.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
4393
Module 18 · Foundation Domain 1 · Background OT threat Unanswered

During a university cyber-range engagement (EDU-RANGE-M18-4393), which evidence best supports an assessment of "OT threat"?

View answer choices
  1. Process-aware telemetry correlating network commands with physical-state changes.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A risk register linking assets to CIA impact ratings.
Practice
4394
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During a financial-services purple-team test (FIN-PT-M18-4394), which evidence best supports an assessment of "OT threat"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. Process-aware telemetry correlating network commands with physical-state changes.
Practice
4395
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During a cloud startup security audit (CLD-AUDIT-M18-4395), which evidence best supports an assessment of "OT threat"?

View answer choices
  1. Process-aware telemetry correlating network commands with physical-state changes.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A risk register linking assets to CIA impact ratings.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
4396
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During a government risk-validation project (GOV-RISK-M18-4396), which evidence best supports an assessment of "OT threat"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Process-aware telemetry correlating network commands with physical-state changes.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
4397
Module 18 · Applied Domain 1 · Background OT threat Unanswered

During an e-commerce application review (ECOM-WEB-M18-4397), which evidence best supports an assessment of "OT threat"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Process-aware telemetry correlating network commands with physical-state changes.
  4. A risk register linking assets to CIA impact ratings.
Practice
4398
Module 18 · Advanced Domain 1 · Background OT threat Unanswered

During a manufacturing and OT security review (MFG-OT-M18-4398), which evidence best supports an assessment of "OT threat"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. Process-aware telemetry correlating network commands with physical-state changes.
Practice
4399
Module 18 · Advanced Domain 1 · Background OT threat Unanswered

During a mobile-services penetration test (MOB-TEST-M18-4399), which evidence best supports an assessment of "OT threat"?

View answer choices
  1. Process-aware telemetry correlating network commands with physical-state changes.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A risk register linking assets to CIA impact ratings.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
4400
Module 18 · Advanced Domain 1 · Background OT threat Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M18-4400), which evidence best supports an assessment of "OT threat"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Process-aware telemetry correlating network commands with physical-state changes.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice