CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 2,451–2,500 of 5,000 matching questions

50 per page
2451
Module 7 · Foundation Domain 1 · Background computer virus Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2451), which risk is most directly associated with "computer virus"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Execution of infected files can spread malicious code and corrupt data.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2452
Module 7 · Foundation Domain 1 · Background computer virus Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2452), which risk is most directly associated with "computer virus"?

View answer choices
  1. Execution of infected files can spread malicious code and corrupt data.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
2453
Module 7 · Foundation Domain 1 · Background computer virus Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2453), which risk is most directly associated with "computer virus"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. Execution of infected files can spread malicious code and corrupt data.
Practice
2454
Module 7 · Applied Domain 1 · Background computer virus Unanswered

During a financial-services purple-team test (FIN-PT-M07-2454), which risk is most directly associated with "computer virus"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Execution of infected files can spread malicious code and corrupt data.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2455
Module 7 · Applied Domain 1 · Background computer virus Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2455), which risk is most directly associated with "computer virus"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Execution of infected files can spread malicious code and corrupt data.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2456
Module 7 · Applied Domain 1 · Background computer virus Unanswered

During a government risk-validation project (GOV-RISK-M07-2456), which risk is most directly associated with "computer virus"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. A control focused on only one objective can leave the other security objectives exposed.
  3. Execution of infected files can spread malicious code and corrupt data.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
2457
Module 7 · Applied Domain 1 · Background computer virus Unanswered

During an e-commerce application review (ECOM-WEB-M07-2457), which risk is most directly associated with "computer virus"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. Execution of infected files can spread malicious code and corrupt data.
Practice
2458
Module 7 · Advanced Domain 1 · Background computer virus Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2458), which risk is most directly associated with "computer virus"?

View answer choices
  1. Execution of infected files can spread malicious code and corrupt data.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2459
Module 7 · Advanced Domain 1 · Background computer virus Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2459), which risk is most directly associated with "computer virus"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Execution of infected files can spread malicious code and corrupt data.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2460
Module 7 · Advanced Domain 1 · Background computer virus Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2460), which risk is most directly associated with "computer virus"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. A control focused on only one objective can leave the other security objectives exposed.
  3. Execution of infected files can spread malicious code and corrupt data.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
2461
Module 7 · Foundation Domain 1 · Background computer virus Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2461), which action most directly controls the risk related to "computer virus"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Block untrusted execution, scan files, patch systems, and maintain recoverable backups.
Practice
2462
Module 7 · Foundation Domain 1 · Background computer virus Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2462), which action most directly controls the risk related to "computer virus"?

View answer choices
  1. Block untrusted execution, scan files, patch systems, and maintain recoverable backups.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2463
Module 7 · Foundation Domain 1 · Background computer virus Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2463), which action most directly controls the risk related to "computer virus"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Block untrusted execution, scan files, patch systems, and maintain recoverable backups.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
2464
Module 7 · Applied Domain 1 · Background computer virus Unanswered

During a financial-services purple-team test (FIN-PT-M07-2464), which action most directly controls the risk related to "computer virus"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Block untrusted execution, scan files, patch systems, and maintain recoverable backups.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2465
Module 7 · Applied Domain 1 · Background computer virus Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2465), which action most directly controls the risk related to "computer virus"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Block untrusted execution, scan files, patch systems, and maintain recoverable backups.
Practice
2466
Module 7 · Applied Domain 1 · Background computer virus Unanswered

During a government risk-validation project (GOV-RISK-M07-2466), which action most directly controls the risk related to "computer virus"?

View answer choices
  1. Block untrusted execution, scan files, patch systems, and maintain recoverable backups.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2467
Module 7 · Applied Domain 1 · Background computer virus Unanswered

During an e-commerce application review (ECOM-WEB-M07-2467), which action most directly controls the risk related to "computer virus"?

View answer choices
  1. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  2. Block untrusted execution, scan files, patch systems, and maintain recoverable backups.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
2468
Module 7 · Advanced Domain 1 · Background computer virus Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2468), which action most directly controls the risk related to "computer virus"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Block untrusted execution, scan files, patch systems, and maintain recoverable backups.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2469
Module 7 · Advanced Domain 1 · Background computer virus Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2469), which action most directly controls the risk related to "computer virus"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Block untrusted execution, scan files, patch systems, and maintain recoverable backups.
Practice
2470
Module 7 · Advanced Domain 1 · Background computer virus Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2470), which action most directly controls the risk related to "computer virus"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Block untrusted execution, scan files, patch systems, and maintain recoverable backups.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
2471
Module 7 · Foundation Domain 1 · Background computer virus Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2471), which evidence best supports an assessment of "computer virus"?

View answer choices
  1. File-integrity changes showing malicious code attached to executable content.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. A risk register linking assets to CIA impact ratings.
Practice
2472
Module 7 · Foundation Domain 1 · Background computer virus Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2472), which evidence best supports an assessment of "computer virus"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. A risk register linking assets to CIA impact ratings.
  4. File-integrity changes showing malicious code attached to executable content.
Practice
2473
Module 7 · Foundation Domain 1 · Background computer virus Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2473), which evidence best supports an assessment of "computer virus"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A risk register linking assets to CIA impact ratings.
  3. File-integrity changes showing malicious code attached to executable content.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
2474
Module 7 · Applied Domain 1 · Background computer virus Unanswered

During a financial-services purple-team test (FIN-PT-M07-2474), which evidence best supports an assessment of "computer virus"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. File-integrity changes showing malicious code attached to executable content.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2475
Module 7 · Applied Domain 1 · Background computer virus Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2475), which evidence best supports an assessment of "computer virus"?

View answer choices
  1. File-integrity changes showing malicious code attached to executable content.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. A risk register linking assets to CIA impact ratings.
Practice
2476
Module 7 · Applied Domain 1 · Background computer virus Unanswered

During a government risk-validation project (GOV-RISK-M07-2476), which evidence best supports an assessment of "computer virus"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. A risk register linking assets to CIA impact ratings.
  4. File-integrity changes showing malicious code attached to executable content.
Practice
2477
Module 7 · Applied Domain 1 · Background computer virus Unanswered

During an e-commerce application review (ECOM-WEB-M07-2477), which evidence best supports an assessment of "computer virus"?

View answer choices
  1. File-integrity changes showing malicious code attached to executable content.
  2. A risk register linking assets to CIA impact ratings.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
2478
Module 7 · Advanced Domain 1 · Background computer virus Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2478), which evidence best supports an assessment of "computer virus"?

View answer choices
  1. A detection matrix showing covered and uncovered ATT&CK techniques.
  2. File-integrity changes showing malicious code attached to executable content.
  3. A risk register linking assets to CIA impact ratings.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2479
Module 7 · Advanced Domain 1 · Background computer virus Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2479), which evidence best supports an assessment of "computer virus"?

View answer choices
  1. File-integrity changes showing malicious code attached to executable content.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A risk register linking assets to CIA impact ratings.
Practice
2480
Module 7 · Advanced Domain 1 · Background computer virus Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2480), which evidence best supports an assessment of "computer virus"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. File-integrity changes showing malicious code attached to executable content.
Practice
2481
Module 7 · Foundation Domain 1 · Background computer worm Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2481), which statement most accurately defines "computer worm"?

View answer choices
  1. Self-propagating malware that spreads between systems without requiring a user to copy it.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
2482
Module 7 · Foundation Domain 1 · Background computer worm Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2482), which statement most accurately defines "computer worm"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. Self-propagating malware that spreads between systems without requiring a user to copy it.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
2483
Module 7 · Foundation Domain 1 · Background computer worm Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2483), which statement most accurately defines "computer worm"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. Self-propagating malware that spreads between systems without requiring a user to copy it.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
2484
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During a financial-services purple-team test (FIN-PT-M07-2484), which statement most accurately defines "computer worm"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. Self-propagating malware that spreads between systems without requiring a user to copy it.
Practice
2485
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2485), which statement most accurately defines "computer worm"?

View answer choices
  1. Self-propagating malware that spreads between systems without requiring a user to copy it.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
2486
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During a government risk-validation project (GOV-RISK-M07-2486), which statement most accurately defines "computer worm"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. Self-propagating malware that spreads between systems without requiring a user to copy it.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
2487
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During an e-commerce application review (ECOM-WEB-M07-2487), which statement most accurately defines "computer worm"?

View answer choices
  1. Self-propagating malware that spreads between systems without requiring a user to copy it.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
2488
Module 7 · Advanced Domain 1 · Background computer worm Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2488), which statement most accurately defines "computer worm"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. Self-propagating malware that spreads between systems without requiring a user to copy it.
Practice
2489
Module 7 · Advanced Domain 1 · Background computer worm Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2489), which statement most accurately defines "computer worm"?

View answer choices
  1. Self-propagating malware that spreads between systems without requiring a user to copy it.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
2490
Module 7 · Advanced Domain 1 · Background computer worm Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2490), which statement most accurately defines "computer worm"?

View answer choices
  1. Self-propagating malware that spreads between systems without requiring a user to copy it.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
2491
Module 7 · Foundation Domain 1 · Background computer worm Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2491), which risk is most directly associated with "computer worm"?

View answer choices
  1. Unmapped detections can leave important adversary techniques without coverage.
  2. Automated propagation can rapidly compromise vulnerable networks and exhaust resources.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2492
Module 7 · Foundation Domain 1 · Background computer worm Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2492), which risk is most directly associated with "computer worm"?

View answer choices
  1. Automated propagation can rapidly compromise vulnerable networks and exhaust resources.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
2493
Module 7 · Foundation Domain 1 · Background computer worm Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2493), which risk is most directly associated with "computer worm"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. Automated propagation can rapidly compromise vulnerable networks and exhaust resources.
Practice
2494
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During a financial-services purple-team test (FIN-PT-M07-2494), which risk is most directly associated with "computer worm"?

View answer choices
  1. Automated propagation can rapidly compromise vulnerable networks and exhaust resources.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2495
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2495), which risk is most directly associated with "computer worm"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Automated propagation can rapidly compromise vulnerable networks and exhaust resources.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2496
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During a government risk-validation project (GOV-RISK-M07-2496), which risk is most directly associated with "computer worm"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. A control focused on only one objective can leave the other security objectives exposed.
  3. Automated propagation can rapidly compromise vulnerable networks and exhaust resources.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
2497
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During an e-commerce application review (ECOM-WEB-M07-2497), which risk is most directly associated with "computer worm"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Automated propagation can rapidly compromise vulnerable networks and exhaust resources.
Practice
2498
Module 7 · Advanced Domain 1 · Background computer worm Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2498), which risk is most directly associated with "computer worm"?

View answer choices
  1. Automated propagation can rapidly compromise vulnerable networks and exhaust resources.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2499
Module 7 · Advanced Domain 1 · Background computer worm Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2499), which risk is most directly associated with "computer worm"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Automated propagation can rapidly compromise vulnerable networks and exhaust resources.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2500
Module 7 · Advanced Domain 1 · Background computer worm Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2500), which risk is most directly associated with "computer worm"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. A control focused on only one objective can leave the other security objectives exposed.
  3. Automated propagation can rapidly compromise vulnerable networks and exhaust resources.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice