CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 2,551–2,600 of 5,000 matching questions

50 per page
2551
Module 7 · Foundation Domain 1 · Background malware Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2551), which evidence best supports an assessment of "malware"?

View answer choices
  1. A detection matrix showing covered and uncovered ATT&CK techniques.
  2. A malware-analysis report combining hashes, behavior, persistence, and network indicators.
  3. A risk register linking assets to CIA impact ratings.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2552
Module 7 · Foundation Domain 1 · Background malware Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2552), which evidence best supports an assessment of "malware"?

View answer choices
  1. A malware-analysis report combining hashes, behavior, persistence, and network indicators.
  2. A risk register linking assets to CIA impact ratings.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
2553
Module 7 · Foundation Domain 1 · Background malware Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2553), which evidence best supports an assessment of "malware"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. A malware-analysis report combining hashes, behavior, persistence, and network indicators.
Practice
2554
Module 7 · Applied Domain 1 · Background malware Unanswered

During a financial-services purple-team test (FIN-PT-M07-2554), which evidence best supports an assessment of "malware"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. A malware-analysis report combining hashes, behavior, persistence, and network indicators.
  4. A risk register linking assets to CIA impact ratings.
Practice
2555
Module 7 · Applied Domain 1 · Background malware Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2555), which evidence best supports an assessment of "malware"?

View answer choices
  1. A detection matrix showing covered and uncovered ATT&CK techniques.
  2. A malware-analysis report combining hashes, behavior, persistence, and network indicators.
  3. A risk register linking assets to CIA impact ratings.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2556
Module 7 · Applied Domain 1 · Background malware Unanswered

During a government risk-validation project (GOV-RISK-M07-2556), which evidence best supports an assessment of "malware"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A risk register linking assets to CIA impact ratings.
  3. A malware-analysis report combining hashes, behavior, persistence, and network indicators.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
2557
Module 7 · Applied Domain 1 · Background malware Unanswered

During an e-commerce application review (ECOM-WEB-M07-2557), which evidence best supports an assessment of "malware"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. A risk register linking assets to CIA impact ratings.
  4. A malware-analysis report combining hashes, behavior, persistence, and network indicators.
Practice
2558
Module 7 · Advanced Domain 1 · Background malware Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2558), which evidence best supports an assessment of "malware"?

View answer choices
  1. A malware-analysis report combining hashes, behavior, persistence, and network indicators.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A risk register linking assets to CIA impact ratings.
Practice
2559
Module 7 · Advanced Domain 1 · Background malware Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2559), which evidence best supports an assessment of "malware"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A malware-analysis report combining hashes, behavior, persistence, and network indicators.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2560
Module 7 · Advanced Domain 1 · Background malware Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2560), which evidence best supports an assessment of "malware"?

View answer choices
  1. A malware-analysis report combining hashes, behavior, persistence, and network indicators.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A risk register linking assets to CIA impact ratings.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
2561
Module 7 · Foundation Domain 1 · Background ransomware Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2561), which statement most accurately defines "ransomware"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. Malware that encrypts or otherwise denies access to data and demands payment.
Practice
2562
Module 7 · Foundation Domain 1 · Background ransomware Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2562), which statement most accurately defines "ransomware"?

View answer choices
  1. Malware that encrypts or otherwise denies access to data and demands payment.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
2563
Module 7 · Foundation Domain 1 · Background ransomware Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2563), which statement most accurately defines "ransomware"?

View answer choices
  1. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  2. Malware that encrypts or otherwise denies access to data and demands payment.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
2564
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During a financial-services purple-team test (FIN-PT-M07-2564), which statement most accurately defines "ransomware"?

View answer choices
  1. Malware that encrypts or otherwise denies access to data and demands payment.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
2565
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2565), which statement most accurately defines "ransomware"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. Malware that encrypts or otherwise denies access to data and demands payment.
Practice
2566
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During a government risk-validation project (GOV-RISK-M07-2566), which statement most accurately defines "ransomware"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. Malware that encrypts or otherwise denies access to data and demands payment.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
2567
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During an e-commerce application review (ECOM-WEB-M07-2567), which statement most accurately defines "ransomware"?

View answer choices
  1. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  2. Malware that encrypts or otherwise denies access to data and demands payment.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
2568
Module 7 · Advanced Domain 1 · Background ransomware Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2568), which statement most accurately defines "ransomware"?

View answer choices
  1. Malware that encrypts or otherwise denies access to data and demands payment.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
2569
Module 7 · Advanced Domain 1 · Background ransomware Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2569), which statement most accurately defines "ransomware"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. Malware that encrypts or otherwise denies access to data and demands payment.
Practice
2570
Module 7 · Advanced Domain 1 · Background ransomware Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2570), which statement most accurately defines "ransomware"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. Malware that encrypts or otherwise denies access to data and demands payment.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
2571
Module 7 · Foundation Domain 1 · Background ransomware Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2571), which risk is most directly associated with "ransomware"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Encryption, exfiltration, and operational disruption can create severe business impact.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2572
Module 7 · Foundation Domain 1 · Background ransomware Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2572), which risk is most directly associated with "ransomware"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Encryption, exfiltration, and operational disruption can create severe business impact.
Practice
2573
Module 7 · Foundation Domain 1 · Background ransomware Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2573), which risk is most directly associated with "ransomware"?

View answer choices
  1. Encryption, exfiltration, and operational disruption can create severe business impact.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
2574
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During a financial-services purple-team test (FIN-PT-M07-2574), which risk is most directly associated with "ransomware"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Encryption, exfiltration, and operational disruption can create severe business impact.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2575
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2575), which risk is most directly associated with "ransomware"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Encryption, exfiltration, and operational disruption can create severe business impact.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2576
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During a government risk-validation project (GOV-RISK-M07-2576), which risk is most directly associated with "ransomware"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. Encryption, exfiltration, and operational disruption can create severe business impact.
Practice
2577
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During an e-commerce application review (ECOM-WEB-M07-2577), which risk is most directly associated with "ransomware"?

View answer choices
  1. Encryption, exfiltration, and operational disruption can create severe business impact.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
2578
Module 7 · Advanced Domain 1 · Background ransomware Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2578), which risk is most directly associated with "ransomware"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Encryption, exfiltration, and operational disruption can create severe business impact.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2579
Module 7 · Advanced Domain 1 · Background ransomware Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2579), which risk is most directly associated with "ransomware"?

View answer choices
  1. Encryption, exfiltration, and operational disruption can create severe business impact.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2580
Module 7 · Advanced Domain 1 · Background ransomware Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2580), which risk is most directly associated with "ransomware"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Encryption, exfiltration, and operational disruption can create severe business impact.
Practice
2581
Module 7 · Foundation Domain 1 · Background ransomware Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2581), which action most directly controls the risk related to "ransomware"?

View answer choices
  1. Use segmentation, least privilege, EDR, immutable backups, and rehearsed recovery.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2582
Module 7 · Foundation Domain 1 · Background ransomware Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2582), which action most directly controls the risk related to "ransomware"?

View answer choices
  1. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  2. Use segmentation, least privilege, EDR, immutable backups, and rehearsed recovery.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
2583
Module 7 · Foundation Domain 1 · Background ransomware Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2583), which action most directly controls the risk related to "ransomware"?

View answer choices
  1. Use segmentation, least privilege, EDR, immutable backups, and rehearsed recovery.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2584
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During a financial-services purple-team test (FIN-PT-M07-2584), which action most directly controls the risk related to "ransomware"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Use segmentation, least privilege, EDR, immutable backups, and rehearsed recovery.
Practice
2585
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2585), which action most directly controls the risk related to "ransomware"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Use segmentation, least privilege, EDR, immutable backups, and rehearsed recovery.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2586
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During a government risk-validation project (GOV-RISK-M07-2586), which action most directly controls the risk related to "ransomware"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Use segmentation, least privilege, EDR, immutable backups, and rehearsed recovery.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
2587
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During an e-commerce application review (ECOM-WEB-M07-2587), which action most directly controls the risk related to "ransomware"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Use segmentation, least privilege, EDR, immutable backups, and rehearsed recovery.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2588
Module 7 · Advanced Domain 1 · Background ransomware Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2588), which action most directly controls the risk related to "ransomware"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Use segmentation, least privilege, EDR, immutable backups, and rehearsed recovery.
Practice
2589
Module 7 · Advanced Domain 1 · Background ransomware Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2589), which action most directly controls the risk related to "ransomware"?

View answer choices
  1. Use segmentation, least privilege, EDR, immutable backups, and rehearsed recovery.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2590
Module 7 · Advanced Domain 1 · Background ransomware Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2590), which action most directly controls the risk related to "ransomware"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Use segmentation, least privilege, EDR, immutable backups, and rehearsed recovery.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2591
Module 7 · Foundation Domain 1 · Background ransomware Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2591), which evidence best supports an assessment of "ransomware"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. Mass file modifications, ransom notes, and connections associated with the intrusion.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2592
Module 7 · Foundation Domain 1 · Background ransomware Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2592), which evidence best supports an assessment of "ransomware"?

View answer choices
  1. Mass file modifications, ransom notes, and connections associated with the intrusion.
  2. A risk register linking assets to CIA impact ratings.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
2593
Module 7 · Foundation Domain 1 · Background ransomware Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2593), which evidence best supports an assessment of "ransomware"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. A risk register linking assets to CIA impact ratings.
  4. Mass file modifications, ransom notes, and connections associated with the intrusion.
Practice
2594
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During a financial-services purple-team test (FIN-PT-M07-2594), which evidence best supports an assessment of "ransomware"?

View answer choices
  1. Mass file modifications, ransom notes, and connections associated with the intrusion.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A risk register linking assets to CIA impact ratings.
Practice
2595
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2595), which evidence best supports an assessment of "ransomware"?

View answer choices
  1. A detection matrix showing covered and uncovered ATT&CK techniques.
  2. Mass file modifications, ransom notes, and connections associated with the intrusion.
  3. A risk register linking assets to CIA impact ratings.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2596
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During a government risk-validation project (GOV-RISK-M07-2596), which evidence best supports an assessment of "ransomware"?

View answer choices
  1. Mass file modifications, ransom notes, and connections associated with the intrusion.
  2. A risk register linking assets to CIA impact ratings.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
2597
Module 7 · Applied Domain 1 · Background ransomware Unanswered

During an e-commerce application review (ECOM-WEB-M07-2597), which evidence best supports an assessment of "ransomware"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. Mass file modifications, ransom notes, and connections associated with the intrusion.
Practice
2598
Module 7 · Advanced Domain 1 · Background ransomware Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2598), which evidence best supports an assessment of "ransomware"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Mass file modifications, ransom notes, and connections associated with the intrusion.
  4. A risk register linking assets to CIA impact ratings.
Practice
2599
Module 7 · Advanced Domain 1 · Background ransomware Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2599), which evidence best supports an assessment of "ransomware"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Mass file modifications, ransom notes, and connections associated with the intrusion.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2600
Module 7 · Advanced Domain 1 · Background ransomware Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2600), which evidence best supports an assessment of "ransomware"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A risk register linking assets to CIA impact ratings.
  3. Mass file modifications, ransom notes, and connections associated with the intrusion.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice