CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 2,601–2,650 of 5,000 matching questions

50 per page
2601
Module 7 · Foundation Domain 1 · Background rootkit Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2601), which statement most accurately defines "rootkit"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. A collection of techniques that hides malicious activity and maintains privileged access.
Practice
2602
Module 7 · Foundation Domain 1 · Background rootkit Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2602), which statement most accurately defines "rootkit"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A collection of techniques that hides malicious activity and maintains privileged access.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
2603
Module 7 · Foundation Domain 1 · Background rootkit Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2603), which statement most accurately defines "rootkit"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A collection of techniques that hides malicious activity and maintains privileged access.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
2604
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During a financial-services purple-team test (FIN-PT-M07-2604), which statement most accurately defines "rootkit"?

View answer choices
  1. A collection of techniques that hides malicious activity and maintains privileged access.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
2605
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2605), which statement most accurately defines "rootkit"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. A collection of techniques that hides malicious activity and maintains privileged access.
Practice
2606
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During a government risk-validation project (GOV-RISK-M07-2606), which statement most accurately defines "rootkit"?

View answer choices
  1. A collection of techniques that hides malicious activity and maintains privileged access.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
2607
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During an e-commerce application review (ECOM-WEB-M07-2607), which statement most accurately defines "rootkit"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A collection of techniques that hides malicious activity and maintains privileged access.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
2608
Module 7 · Advanced Domain 1 · Background rootkit Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2608), which statement most accurately defines "rootkit"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. A collection of techniques that hides malicious activity and maintains privileged access.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
2609
Module 7 · Advanced Domain 1 · Background rootkit Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2609), which statement most accurately defines "rootkit"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A collection of techniques that hides malicious activity and maintains privileged access.
Practice
2610
Module 7 · Advanced Domain 1 · Background rootkit Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2610), which statement most accurately defines "rootkit"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A collection of techniques that hides malicious activity and maintains privileged access.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
2611
Module 7 · Foundation Domain 1 · Background rootkit Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2611), which risk is most directly associated with "rootkit"?

View answer choices
  1. Kernel or boot-level manipulation can conceal processes, files, and attacker persistence.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2612
Module 7 · Foundation Domain 1 · Background rootkit Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2612), which risk is most directly associated with "rootkit"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Kernel or boot-level manipulation can conceal processes, files, and attacker persistence.
Practice
2613
Module 7 · Foundation Domain 1 · Background rootkit Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2613), which risk is most directly associated with "rootkit"?

View answer choices
  1. Kernel or boot-level manipulation can conceal processes, files, and attacker persistence.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
2614
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During a financial-services purple-team test (FIN-PT-M07-2614), which risk is most directly associated with "rootkit"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Kernel or boot-level manipulation can conceal processes, files, and attacker persistence.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2615
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2615), which risk is most directly associated with "rootkit"?

View answer choices
  1. Kernel or boot-level manipulation can conceal processes, files, and attacker persistence.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2616
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During a government risk-validation project (GOV-RISK-M07-2616), which risk is most directly associated with "rootkit"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Kernel or boot-level manipulation can conceal processes, files, and attacker persistence.
Practice
2617
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During an e-commerce application review (ECOM-WEB-M07-2617), which risk is most directly associated with "rootkit"?

View answer choices
  1. Kernel or boot-level manipulation can conceal processes, files, and attacker persistence.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
2618
Module 7 · Advanced Domain 1 · Background rootkit Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2618), which risk is most directly associated with "rootkit"?

View answer choices
  1. Unmapped detections can leave important adversary techniques without coverage.
  2. Kernel or boot-level manipulation can conceal processes, files, and attacker persistence.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2619
Module 7 · Advanced Domain 1 · Background rootkit Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2619), which risk is most directly associated with "rootkit"?

View answer choices
  1. Kernel or boot-level manipulation can conceal processes, files, and attacker persistence.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2620
Module 7 · Advanced Domain 1 · Background rootkit Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2620), which risk is most directly associated with "rootkit"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Kernel or boot-level manipulation can conceal processes, files, and attacker persistence.
Practice
2621
Module 7 · Foundation Domain 1 · Background rootkit Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2621), which action most directly controls the risk related to "rootkit"?

View answer choices
  1. Use secure boot, integrity monitoring, offline analysis, and trusted reimaging.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2622
Module 7 · Foundation Domain 1 · Background rootkit Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2622), which action most directly controls the risk related to "rootkit"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Use secure boot, integrity monitoring, offline analysis, and trusted reimaging.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
2623
Module 7 · Foundation Domain 1 · Background rootkit Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2623), which action most directly controls the risk related to "rootkit"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Use secure boot, integrity monitoring, offline analysis, and trusted reimaging.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2624
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During a financial-services purple-team test (FIN-PT-M07-2624), which action most directly controls the risk related to "rootkit"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Use secure boot, integrity monitoring, offline analysis, and trusted reimaging.
Practice
2625
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2625), which action most directly controls the risk related to "rootkit"?

View answer choices
  1. Use secure boot, integrity monitoring, offline analysis, and trusted reimaging.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2626
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During a government risk-validation project (GOV-RISK-M07-2626), which action most directly controls the risk related to "rootkit"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Use secure boot, integrity monitoring, offline analysis, and trusted reimaging.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
2627
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During an e-commerce application review (ECOM-WEB-M07-2627), which action most directly controls the risk related to "rootkit"?

View answer choices
  1. Use secure boot, integrity monitoring, offline analysis, and trusted reimaging.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2628
Module 7 · Advanced Domain 1 · Background rootkit Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2628), which action most directly controls the risk related to "rootkit"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Use secure boot, integrity monitoring, offline analysis, and trusted reimaging.
Practice
2629
Module 7 · Advanced Domain 1 · Background rootkit Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2629), which action most directly controls the risk related to "rootkit"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Use secure boot, integrity monitoring, offline analysis, and trusted reimaging.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2630
Module 7 · Advanced Domain 1 · Background rootkit Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2630), which action most directly controls the risk related to "rootkit"?

View answer choices
  1. Use secure boot, integrity monitoring, offline analysis, and trusted reimaging.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2631
Module 7 · Foundation Domain 1 · Background rootkit Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2631), which evidence best supports an assessment of "rootkit"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Integrity differences found from a trusted offline environment.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2632
Module 7 · Foundation Domain 1 · Background rootkit Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2632), which evidence best supports an assessment of "rootkit"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A risk register linking assets to CIA impact ratings.
  3. Integrity differences found from a trusted offline environment.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
2633
Module 7 · Foundation Domain 1 · Background rootkit Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2633), which evidence best supports an assessment of "rootkit"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. Integrity differences found from a trusted offline environment.
Practice
2634
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During a financial-services purple-team test (FIN-PT-M07-2634), which evidence best supports an assessment of "rootkit"?

View answer choices
  1. Integrity differences found from a trusted offline environment.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. A risk register linking assets to CIA impact ratings.
Practice
2635
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2635), which evidence best supports an assessment of "rootkit"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Integrity differences found from a trusted offline environment.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2636
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During a government risk-validation project (GOV-RISK-M07-2636), which evidence best supports an assessment of "rootkit"?

View answer choices
  1. Integrity differences found from a trusted offline environment.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A risk register linking assets to CIA impact ratings.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
2637
Module 7 · Applied Domain 1 · Background rootkit Unanswered

During an e-commerce application review (ECOM-WEB-M07-2637), which evidence best supports an assessment of "rootkit"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. Integrity differences found from a trusted offline environment.
Practice
2638
Module 7 · Advanced Domain 1 · Background rootkit Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2638), which evidence best supports an assessment of "rootkit"?

View answer choices
  1. Integrity differences found from a trusted offline environment.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. A risk register linking assets to CIA impact ratings.
Practice
2639
Module 7 · Advanced Domain 1 · Background rootkit Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2639), which evidence best supports an assessment of "rootkit"?

View answer choices
  1. A detection matrix showing covered and uncovered ATT&CK techniques.
  2. Integrity differences found from a trusted offline environment.
  3. A risk register linking assets to CIA impact ratings.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2640
Module 7 · Advanced Domain 1 · Background rootkit Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2640), which evidence best supports an assessment of "rootkit"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. Integrity differences found from a trusted offline environment.
Practice
2641
Module 7 · Foundation Domain 2 · Analysis / Assessment malware analysis Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2641), which statement most accurately defines "malware analysis"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  3. Static and dynamic examination of suspicious code to determine behavior and indicators.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
2642
Module 7 · Foundation Domain 2 · Analysis / Assessment malware analysis Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2642), which statement most accurately defines "malware analysis"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Static and dynamic examination of suspicious code to determine behavior and indicators.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
2643
Module 7 · Foundation Domain 2 · Analysis / Assessment malware analysis Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2643), which statement most accurately defines "malware analysis"?

View answer choices
  1. Static and dynamic examination of suspicious code to determine behavior and indicators.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
2644
Module 7 · Applied Domain 2 · Analysis / Assessment malware analysis Unanswered

During a financial-services purple-team test (FIN-PT-M07-2644), which statement most accurately defines "malware analysis"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Static and dynamic examination of suspicious code to determine behavior and indicators.
Practice
2645
Module 7 · Applied Domain 2 · Analysis / Assessment malware analysis Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2645), which statement most accurately defines "malware analysis"?

View answer choices
  1. Static and dynamic examination of suspicious code to determine behavior and indicators.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
2646
Module 7 · Applied Domain 2 · Analysis / Assessment malware analysis Unanswered

During a government risk-validation project (GOV-RISK-M07-2646), which statement most accurately defines "malware analysis"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Static and dynamic examination of suspicious code to determine behavior and indicators.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
2647
Module 7 · Applied Domain 2 · Analysis / Assessment malware analysis Unanswered

During an e-commerce application review (ECOM-WEB-M07-2647), which statement most accurately defines "malware analysis"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Static and dynamic examination of suspicious code to determine behavior and indicators.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
2648
Module 7 · Advanced Domain 2 · Analysis / Assessment malware analysis Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2648), which statement most accurately defines "malware analysis"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Static and dynamic examination of suspicious code to determine behavior and indicators.
Practice
2649
Module 7 · Advanced Domain 2 · Analysis / Assessment malware analysis Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2649), which statement most accurately defines "malware analysis"?

View answer choices
  1. Static and dynamic examination of suspicious code to determine behavior and indicators.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
2650
Module 7 · Advanced Domain 2 · Analysis / Assessment malware analysis Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2650), which statement most accurately defines "malware analysis"?

View answer choices
  1. Static and dynamic examination of suspicious code to determine behavior and indicators.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice