CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 4,901–4,950 of 5,000 matching questions

50 per page
4901
Module 20 · Foundation Domain 3 · Security encryption at rest Unanswered

During an authorized retail-company assessment (RET-LAB-M20-4901), which action most directly controls the risk related to "encryption at rest"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Use approved encryption with protected keys, rotation, access control, and recovery planning.
Practice
4902
Module 20 · Foundation Domain 3 · Security encryption at rest Unanswered

During a hospital incident-response exercise (HLT-SOC-M20-4902), which action most directly controls the risk related to "encryption at rest"?

View answer choices
  1. Use approved encryption with protected keys, rotation, access control, and recovery planning.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
4903
Module 20 · Foundation Domain 3 · Security encryption at rest Unanswered

During a university cyber-range engagement (EDU-RANGE-M20-4903), which action most directly controls the risk related to "encryption at rest"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Use approved encryption with protected keys, rotation, access control, and recovery planning.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
4904
Module 20 · Applied Domain 3 · Security encryption at rest Unanswered

During a financial-services purple-team test (FIN-PT-M20-4904), which action most directly controls the risk related to "encryption at rest"?

View answer choices
  1. Use approved encryption with protected keys, rotation, access control, and recovery planning.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
4905
Module 20 · Applied Domain 3 · Security encryption at rest Unanswered

During a cloud startup security audit (CLD-AUDIT-M20-4905), which action most directly controls the risk related to "encryption at rest"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Use approved encryption with protected keys, rotation, access control, and recovery planning.
Practice
4906
Module 20 · Applied Domain 3 · Security encryption at rest Unanswered

During a government risk-validation project (GOV-RISK-M20-4906), which action most directly controls the risk related to "encryption at rest"?

View answer choices
  1. Use approved encryption with protected keys, rotation, access control, and recovery planning.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
4907
Module 20 · Applied Domain 3 · Security encryption at rest Unanswered

During an e-commerce application review (ECOM-WEB-M20-4907), which action most directly controls the risk related to "encryption at rest"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Use approved encryption with protected keys, rotation, access control, and recovery planning.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
4908
Module 20 · Advanced Domain 3 · Security encryption at rest Unanswered

During a manufacturing and OT security review (MFG-OT-M20-4908), which action most directly controls the risk related to "encryption at rest"?

View answer choices
  1. Use approved encryption with protected keys, rotation, access control, and recovery planning.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
4909
Module 20 · Advanced Domain 3 · Security encryption at rest Unanswered

During a mobile-services penetration test (MOB-TEST-M20-4909), which action most directly controls the risk related to "encryption at rest"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Use approved encryption with protected keys, rotation, access control, and recovery planning.
Practice
4910
Module 20 · Advanced Domain 3 · Security encryption at rest Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M20-4910), which action most directly controls the risk related to "encryption at rest"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Use approved encryption with protected keys, rotation, access control, and recovery planning.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
4911
Module 20 · Foundation Domain 3 · Security encryption at rest Unanswered

During an authorized retail-company assessment (RET-LAB-M20-4911), which evidence best supports an assessment of "encryption at rest"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. Storage configuration and key-service logs proving encryption and authorized key use.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
4912
Module 20 · Foundation Domain 3 · Security encryption at rest Unanswered

During a hospital incident-response exercise (HLT-SOC-M20-4912), which evidence best supports an assessment of "encryption at rest"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. Storage configuration and key-service logs proving encryption and authorized key use.
Practice
4913
Module 20 · Foundation Domain 3 · Security encryption at rest Unanswered

During a university cyber-range engagement (EDU-RANGE-M20-4913), which evidence best supports an assessment of "encryption at rest"?

View answer choices
  1. Storage configuration and key-service logs proving encryption and authorized key use.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
4914
Module 20 · Applied Domain 3 · Security encryption at rest Unanswered

During a financial-services purple-team test (FIN-PT-M20-4914), which evidence best supports an assessment of "encryption at rest"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. Storage configuration and key-service logs proving encryption and authorized key use.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
4915
Module 20 · Applied Domain 3 · Security encryption at rest Unanswered

During a cloud startup security audit (CLD-AUDIT-M20-4915), which evidence best supports an assessment of "encryption at rest"?

View answer choices
  1. Storage configuration and key-service logs proving encryption and authorized key use.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
4916
Module 20 · Applied Domain 3 · Security encryption at rest Unanswered

During a government risk-validation project (GOV-RISK-M20-4916), which evidence best supports an assessment of "encryption at rest"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. Storage configuration and key-service logs proving encryption and authorized key use.
Practice
4917
Module 20 · Applied Domain 3 · Security encryption at rest Unanswered

During an e-commerce application review (ECOM-WEB-M20-4917), which evidence best supports an assessment of "encryption at rest"?

View answer choices
  1. Storage configuration and key-service logs proving encryption and authorized key use.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
4918
Module 20 · Advanced Domain 3 · Security encryption at rest Unanswered

During a manufacturing and OT security review (MFG-OT-M20-4918), which evidence best supports an assessment of "encryption at rest"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. Storage configuration and key-service logs proving encryption and authorized key use.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
4919
Module 20 · Advanced Domain 3 · Security encryption at rest Unanswered

During a mobile-services penetration test (MOB-TEST-M20-4919), which evidence best supports an assessment of "encryption at rest"?

View answer choices
  1. Storage configuration and key-service logs proving encryption and authorized key use.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
4920
Module 20 · Advanced Domain 3 · Security encryption at rest Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M20-4920), which evidence best supports an assessment of "encryption at rest"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. Storage configuration and key-service logs proving encryption and authorized key use.
Practice
4921
Module 20 · Foundation Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During an authorized retail-company assessment (RET-LAB-M20-4921), which statement most accurately defines "GnuPG"?

View answer choices
  1. A tool implementing OpenPGP for encryption, signing, and key management.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
4922
Module 20 · Foundation Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a hospital incident-response exercise (HLT-SOC-M20-4922), which statement most accurately defines "GnuPG"?

View answer choices
  1. A search service that indexes Internet-connected devices and service banners.
  2. A tool implementing OpenPGP for encryption, signing, and key management.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
4923
Module 20 · Foundation Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a university cyber-range engagement (EDU-RANGE-M20-4923), which statement most accurately defines "GnuPG"?

View answer choices
  1. A tool implementing OpenPGP for encryption, signing, and key management.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
4924
Module 20 · Applied Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a financial-services purple-team test (FIN-PT-M20-4924), which statement most accurately defines "GnuPG"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A tool implementing OpenPGP for encryption, signing, and key management.
Practice
4925
Module 20 · Applied Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a cloud startup security audit (CLD-AUDIT-M20-4925), which statement most accurately defines "GnuPG"?

View answer choices
  1. A tool implementing OpenPGP for encryption, signing, and key management.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
4926
Module 20 · Applied Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a government risk-validation project (GOV-RISK-M20-4926), which statement most accurately defines "GnuPG"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A tool implementing OpenPGP for encryption, signing, and key management.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
4927
Module 20 · Applied Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During an e-commerce application review (ECOM-WEB-M20-4927), which statement most accurately defines "GnuPG"?

View answer choices
  1. A tool implementing OpenPGP for encryption, signing, and key management.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
4928
Module 20 · Advanced Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a manufacturing and OT security review (MFG-OT-M20-4928), which statement most accurately defines "GnuPG"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A tool implementing OpenPGP for encryption, signing, and key management.
Practice
4929
Module 20 · Advanced Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a mobile-services penetration test (MOB-TEST-M20-4929), which statement most accurately defines "GnuPG"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A tool implementing OpenPGP for encryption, signing, and key management.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
4930
Module 20 · Advanced Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M20-4930), which statement most accurately defines "GnuPG"?

View answer choices
  1. A tool implementing OpenPGP for encryption, signing, and key management.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
4931
Module 20 · Foundation Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During an authorized retail-company assessment (RET-LAB-M20-4931), which risk is most directly associated with "GnuPG"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Incorrect recipient keys or weak key validation can expose data or enable impersonation.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Automated modules can query third parties or collect data outside scope.
Practice
4932
Module 20 · Foundation Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a hospital incident-response exercise (HLT-SOC-M20-4932), which risk is most directly associated with "GnuPG"?

View answer choices
  1. Incorrect recipient keys or weak key validation can expose data or enable impersonation.
  2. Automated modules can query third parties or collect data outside scope.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
4933
Module 20 · Foundation Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a university cyber-range engagement (EDU-RANGE-M20-4933), which risk is most directly associated with "GnuPG"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Incorrect recipient keys or weak key validation can expose data or enable impersonation.
Practice
4934
Module 20 · Applied Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a financial-services purple-team test (FIN-PT-M20-4934), which risk is most directly associated with "GnuPG"?

View answer choices
  1. Incorrect recipient keys or weak key validation can expose data or enable impersonation.
  2. Automated modules can query third parties or collect data outside scope.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
4935
Module 20 · Applied Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a cloud startup security audit (CLD-AUDIT-M20-4935), which risk is most directly associated with "GnuPG"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Incorrect recipient keys or weak key validation can expose data or enable impersonation.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Automated modules can query third parties or collect data outside scope.
Practice
4936
Module 20 · Applied Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a government risk-validation project (GOV-RISK-M20-4936), which risk is most directly associated with "GnuPG"?

View answer choices
  1. Incorrect recipient keys or weak key validation can expose data or enable impersonation.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Automated modules can query third parties or collect data outside scope.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
4937
Module 20 · Applied Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During an e-commerce application review (ECOM-WEB-M20-4937), which risk is most directly associated with "GnuPG"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Incorrect recipient keys or weak key validation can expose data or enable impersonation.
Practice
4938
Module 20 · Advanced Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a manufacturing and OT security review (MFG-OT-M20-4938), which risk is most directly associated with "GnuPG"?

View answer choices
  1. Incorrect recipient keys or weak key validation can expose data or enable impersonation.
  2. Automated modules can query third parties or collect data outside scope.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
4939
Module 20 · Advanced Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a mobile-services penetration test (MOB-TEST-M20-4939), which risk is most directly associated with "GnuPG"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Incorrect recipient keys or weak key validation can expose data or enable impersonation.
  4. Automated modules can query third parties or collect data outside scope.
Practice
4940
Module 20 · Advanced Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M20-4940), which risk is most directly associated with "GnuPG"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Incorrect recipient keys or weak key validation can expose data or enable impersonation.
Practice
4941
Module 20 · Foundation Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During an authorized retail-company assessment (RET-LAB-M20-4941), which action most directly controls the risk related to "GnuPG"?

View answer choices
  1. Verify fingerprints, protect private keys, and manage revocation and expiration.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
4942
Module 20 · Foundation Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a hospital incident-response exercise (HLT-SOC-M20-4942), which action most directly controls the risk related to "GnuPG"?

View answer choices
  1. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  2. Verify fingerprints, protect private keys, and manage revocation and expiration.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
4943
Module 20 · Foundation Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a university cyber-range engagement (EDU-RANGE-M20-4943), which action most directly controls the risk related to "GnuPG"?

View answer choices
  1. Verify fingerprints, protect private keys, and manage revocation and expiration.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
4944
Module 20 · Applied Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a financial-services purple-team test (FIN-PT-M20-4944), which action most directly controls the risk related to "GnuPG"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Verify fingerprints, protect private keys, and manage revocation and expiration.
Practice
4945
Module 20 · Applied Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a cloud startup security audit (CLD-AUDIT-M20-4945), which action most directly controls the risk related to "GnuPG"?

View answer choices
  1. Verify fingerprints, protect private keys, and manage revocation and expiration.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
4946
Module 20 · Applied Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a government risk-validation project (GOV-RISK-M20-4946), which action most directly controls the risk related to "GnuPG"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Verify fingerprints, protect private keys, and manage revocation and expiration.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
4947
Module 20 · Applied Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During an e-commerce application review (ECOM-WEB-M20-4947), which action most directly controls the risk related to "GnuPG"?

View answer choices
  1. Verify fingerprints, protect private keys, and manage revocation and expiration.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
4948
Module 20 · Advanced Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a manufacturing and OT security review (MFG-OT-M20-4948), which action most directly controls the risk related to "GnuPG"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Verify fingerprints, protect private keys, and manage revocation and expiration.
Practice
4949
Module 20 · Advanced Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a mobile-services penetration test (MOB-TEST-M20-4949), which action most directly controls the risk related to "GnuPG"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Verify fingerprints, protect private keys, and manage revocation and expiration.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
4950
Module 20 · Advanced Domain 4 · Tools / Systems / Programs GnuPG Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M20-4950), which action most directly controls the risk related to "GnuPG"?

View answer choices
  1. Verify fingerprints, protect private keys, and manage revocation and expiration.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice