CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 2,351–2,400 of 5,000 matching questions

50 per page
2351
Module 6 · Foundation Domain 4 · Tools / Systems / Programs THC Hydra Unanswered

During an authorized retail-company assessment (RET-LAB-M06-2351), which evidence best supports an assessment of "THC Hydra"?

View answer choices
  1. Search results validated against the organization’s current external inventory.
  2. Authentication logs matching the authorized source, account list, and attempt rate.
  3. A relationship graph retaining sources and transformation history.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
2352
Module 6 · Foundation Domain 4 · Tools / Systems / Programs THC Hydra Unanswered

During a hospital incident-response exercise (HLT-SOC-M06-2352), which evidence best supports an assessment of "THC Hydra"?

View answer choices
  1. Authentication logs matching the authorized source, account list, and attempt rate.
  2. A relationship graph retaining sources and transformation history.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Search results validated against the organization’s current external inventory.
Practice
2353
Module 6 · Foundation Domain 4 · Tools / Systems / Programs THC Hydra Unanswered

During a university cyber-range engagement (EDU-RANGE-M06-2353), which evidence best supports an assessment of "THC Hydra"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. Search results validated against the organization’s current external inventory.
  3. A relationship graph retaining sources and transformation history.
  4. Authentication logs matching the authorized source, account list, and attempt rate.
Practice
2354
Module 6 · Applied Domain 4 · Tools / Systems / Programs THC Hydra Unanswered

During a financial-services purple-team test (FIN-PT-M06-2354), which evidence best supports an assessment of "THC Hydra"?

View answer choices
  1. Authentication logs matching the authorized source, account list, and attempt rate.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A relationship graph retaining sources and transformation history.
Practice
2355
Module 6 · Applied Domain 4 · Tools / Systems / Programs THC Hydra Unanswered

During a cloud startup security audit (CLD-AUDIT-M06-2355), which evidence best supports an assessment of "THC Hydra"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Authentication logs matching the authorized source, account list, and attempt rate.
  3. Search results validated against the organization’s current external inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
2356
Module 6 · Applied Domain 4 · Tools / Systems / Programs THC Hydra Unanswered

During a government risk-validation project (GOV-RISK-M06-2356), which evidence best supports an assessment of "THC Hydra"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. A relationship graph retaining sources and transformation history.
  3. Authentication logs matching the authorized source, account list, and attempt rate.
  4. Search results validated against the organization’s current external inventory.
Practice
2357
Module 6 · Applied Domain 4 · Tools / Systems / Programs THC Hydra Unanswered

During an e-commerce application review (ECOM-WEB-M06-2357), which evidence best supports an assessment of "THC Hydra"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Authentication logs matching the authorized source, account list, and attempt rate.
Practice
2358
Module 6 · Advanced Domain 4 · Tools / Systems / Programs THC Hydra Unanswered

During a manufacturing and OT security review (MFG-OT-M06-2358), which evidence best supports an assessment of "THC Hydra"?

View answer choices
  1. Authentication logs matching the authorized source, account list, and attempt rate.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. Search results validated against the organization’s current external inventory.
  4. A relationship graph retaining sources and transformation history.
Practice
2359
Module 6 · Advanced Domain 4 · Tools / Systems / Programs THC Hydra Unanswered

During a mobile-services penetration test (MOB-TEST-M06-2359), which evidence best supports an assessment of "THC Hydra"?

View answer choices
  1. Search results validated against the organization’s current external inventory.
  2. Authentication logs matching the authorized source, account list, and attempt rate.
  3. A relationship graph retaining sources and transformation history.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
2360
Module 6 · Advanced Domain 4 · Tools / Systems / Programs THC Hydra Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M06-2360), which evidence best supports an assessment of "THC Hydra"?

View answer choices
  1. Authentication logs matching the authorized source, account list, and attempt rate.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. A relationship graph retaining sources and transformation history.
  4. Search results validated against the organization’s current external inventory.
Practice
2361
Module 7 · Foundation Domain 1 · Background Trojan horse Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2361), which statement most accurately defines "Trojan horse"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. Malware disguised as legitimate software that relies on a user or process to install it.
Practice
2362
Module 7 · Foundation Domain 1 · Background Trojan horse Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2362), which statement most accurately defines "Trojan horse"?

View answer choices
  1. Malware disguised as legitimate software that relies on a user or process to install it.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
2363
Module 7 · Foundation Domain 1 · Background Trojan horse Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2363), which statement most accurately defines "Trojan horse"?

View answer choices
  1. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  2. Malware disguised as legitimate software that relies on a user or process to install it.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
2364
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During a financial-services purple-team test (FIN-PT-M07-2364), which statement most accurately defines "Trojan horse"?

View answer choices
  1. Malware disguised as legitimate software that relies on a user or process to install it.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
2365
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2365), which statement most accurately defines "Trojan horse"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. Malware disguised as legitimate software that relies on a user or process to install it.
Practice
2366
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During a government risk-validation project (GOV-RISK-M07-2366), which statement most accurately defines "Trojan horse"?

View answer choices
  1. Malware disguised as legitimate software that relies on a user or process to install it.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
2367
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During an e-commerce application review (ECOM-WEB-M07-2367), which statement most accurately defines "Trojan horse"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. Malware disguised as legitimate software that relies on a user or process to install it.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
2368
Module 7 · Advanced Domain 1 · Background Trojan horse Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2368), which statement most accurately defines "Trojan horse"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. Malware disguised as legitimate software that relies on a user or process to install it.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
2369
Module 7 · Advanced Domain 1 · Background Trojan horse Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2369), which statement most accurately defines "Trojan horse"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. Malware disguised as legitimate software that relies on a user or process to install it.
Practice
2370
Module 7 · Advanced Domain 1 · Background Trojan horse Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2370), which statement most accurately defines "Trojan horse"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. Malware disguised as legitimate software that relies on a user or process to install it.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
2371
Module 7 · Foundation Domain 1 · Background Trojan horse Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2371), which risk is most directly associated with "Trojan horse"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. A trusted-looking package can deliver backdoors, steal credentials, or install other payloads.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2372
Module 7 · Foundation Domain 1 · Background Trojan horse Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2372), which risk is most directly associated with "Trojan horse"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. A trusted-looking package can deliver backdoors, steal credentials, or install other payloads.
Practice
2373
Module 7 · Foundation Domain 1 · Background Trojan horse Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2373), which risk is most directly associated with "Trojan horse"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. A control focused on only one objective can leave the other security objectives exposed.
  3. A trusted-looking package can deliver backdoors, steal credentials, or install other payloads.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
2374
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During a financial-services purple-team test (FIN-PT-M07-2374), which risk is most directly associated with "Trojan horse"?

View answer choices
  1. Unmapped detections can leave important adversary techniques without coverage.
  2. A trusted-looking package can deliver backdoors, steal credentials, or install other payloads.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2375
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2375), which risk is most directly associated with "Trojan horse"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. A trusted-looking package can deliver backdoors, steal credentials, or install other payloads.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2376
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During a government risk-validation project (GOV-RISK-M07-2376), which risk is most directly associated with "Trojan horse"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. A trusted-looking package can deliver backdoors, steal credentials, or install other payloads.
Practice
2377
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During an e-commerce application review (ECOM-WEB-M07-2377), which risk is most directly associated with "Trojan horse"?

View answer choices
  1. A trusted-looking package can deliver backdoors, steal credentials, or install other payloads.
  2. A control focused on only one objective can leave the other security objectives exposed.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
2378
Module 7 · Advanced Domain 1 · Background Trojan horse Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2378), which risk is most directly associated with "Trojan horse"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. A trusted-looking package can deliver backdoors, steal credentials, or install other payloads.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2379
Module 7 · Advanced Domain 1 · Background Trojan horse Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2379), which risk is most directly associated with "Trojan horse"?

View answer choices
  1. A trusted-looking package can deliver backdoors, steal credentials, or install other payloads.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2380
Module 7 · Advanced Domain 1 · Background Trojan horse Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2380), which risk is most directly associated with "Trojan horse"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. A trusted-looking package can deliver backdoors, steal credentials, or install other payloads.
Practice
2381
Module 7 · Foundation Domain 1 · Background Trojan horse Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2381), which action most directly controls the risk related to "Trojan horse"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Verify software provenance, control execution, and monitor suspicious child processes.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2382
Module 7 · Foundation Domain 1 · Background Trojan horse Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2382), which action most directly controls the risk related to "Trojan horse"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Verify software provenance, control execution, and monitor suspicious child processes.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
2383
Module 7 · Foundation Domain 1 · Background Trojan horse Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2383), which action most directly controls the risk related to "Trojan horse"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Verify software provenance, control execution, and monitor suspicious child processes.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2384
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During a financial-services purple-team test (FIN-PT-M07-2384), which action most directly controls the risk related to "Trojan horse"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Verify software provenance, control execution, and monitor suspicious child processes.
Practice
2385
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2385), which action most directly controls the risk related to "Trojan horse"?

View answer choices
  1. Verify software provenance, control execution, and monitor suspicious child processes.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2386
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During a government risk-validation project (GOV-RISK-M07-2386), which action most directly controls the risk related to "Trojan horse"?

View answer choices
  1. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  2. Verify software provenance, control execution, and monitor suspicious child processes.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
2387
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During an e-commerce application review (ECOM-WEB-M07-2387), which action most directly controls the risk related to "Trojan horse"?

View answer choices
  1. Verify software provenance, control execution, and monitor suspicious child processes.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2388
Module 7 · Advanced Domain 1 · Background Trojan horse Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2388), which action most directly controls the risk related to "Trojan horse"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Verify software provenance, control execution, and monitor suspicious child processes.
Practice
2389
Module 7 · Advanced Domain 1 · Background Trojan horse Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2389), which action most directly controls the risk related to "Trojan horse"?

View answer choices
  1. Verify software provenance, control execution, and monitor suspicious child processes.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2390
Module 7 · Advanced Domain 1 · Background Trojan horse Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2390), which action most directly controls the risk related to "Trojan horse"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Verify software provenance, control execution, and monitor suspicious child processes.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2391
Module 7 · Foundation Domain 1 · Background Trojan horse Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2391), which evidence best supports an assessment of "Trojan horse"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. An unsigned or altered application spawning unexpected processes or connections.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2392
Module 7 · Foundation Domain 1 · Background Trojan horse Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2392), which evidence best supports an assessment of "Trojan horse"?

View answer choices
  1. An unsigned or altered application spawning unexpected processes or connections.
  2. A risk register linking assets to CIA impact ratings.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
2393
Module 7 · Foundation Domain 1 · Background Trojan horse Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2393), which evidence best supports an assessment of "Trojan horse"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. An unsigned or altered application spawning unexpected processes or connections.
Practice
2394
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During a financial-services purple-team test (FIN-PT-M07-2394), which evidence best supports an assessment of "Trojan horse"?

View answer choices
  1. An unsigned or altered application spawning unexpected processes or connections.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. A risk register linking assets to CIA impact ratings.
Practice
2395
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2395), which evidence best supports an assessment of "Trojan horse"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. An unsigned or altered application spawning unexpected processes or connections.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2396
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During a government risk-validation project (GOV-RISK-M07-2396), which evidence best supports an assessment of "Trojan horse"?

View answer choices
  1. An unsigned or altered application spawning unexpected processes or connections.
  2. A risk register linking assets to CIA impact ratings.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
2397
Module 7 · Applied Domain 1 · Background Trojan horse Unanswered

During an e-commerce application review (ECOM-WEB-M07-2397), which evidence best supports an assessment of "Trojan horse"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. An unsigned or altered application spawning unexpected processes or connections.
Practice
2398
Module 7 · Advanced Domain 1 · Background Trojan horse Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2398), which evidence best supports an assessment of "Trojan horse"?

View answer choices
  1. An unsigned or altered application spawning unexpected processes or connections.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. A risk register linking assets to CIA impact ratings.
Practice
2399
Module 7 · Advanced Domain 1 · Background Trojan horse Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2399), which evidence best supports an assessment of "Trojan horse"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. An unsigned or altered application spawning unexpected processes or connections.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2400
Module 7 · Advanced Domain 1 · Background Trojan horse Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2400), which evidence best supports an assessment of "Trojan horse"?

View answer choices
  1. An unsigned or altered application spawning unexpected processes or connections.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A risk register linking assets to CIA impact ratings.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice