CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 2,701–2,750 of 5,000 matching questions

50 per page
2701
Module 7 · Foundation Domain 3 · Security anti-malware control Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2701), which action most directly controls the risk related to "anti-malware control"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Combine signatures, behavior analytics, updates, tamper protection, and centralized monitoring.
Practice
2702
Module 7 · Foundation Domain 3 · Security anti-malware control Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2702), which action most directly controls the risk related to "anti-malware control"?

View answer choices
  1. Combine signatures, behavior analytics, updates, tamper protection, and centralized monitoring.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
2703
Module 7 · Foundation Domain 3 · Security anti-malware control Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2703), which action most directly controls the risk related to "anti-malware control"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Combine signatures, behavior analytics, updates, tamper protection, and centralized monitoring.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
2704
Module 7 · Applied Domain 3 · Security anti-malware control Unanswered

During a financial-services purple-team test (FIN-PT-M07-2704), which action most directly controls the risk related to "anti-malware control"?

View answer choices
  1. Combine signatures, behavior analytics, updates, tamper protection, and centralized monitoring.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
2705
Module 7 · Applied Domain 3 · Security anti-malware control Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2705), which action most directly controls the risk related to "anti-malware control"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Combine signatures, behavior analytics, updates, tamper protection, and centralized monitoring.
Practice
2706
Module 7 · Applied Domain 3 · Security anti-malware control Unanswered

During a government risk-validation project (GOV-RISK-M07-2706), which action most directly controls the risk related to "anti-malware control"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Combine signatures, behavior analytics, updates, tamper protection, and centralized monitoring.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
2707
Module 7 · Applied Domain 3 · Security anti-malware control Unanswered

During an e-commerce application review (ECOM-WEB-M07-2707), which action most directly controls the risk related to "anti-malware control"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Combine signatures, behavior analytics, updates, tamper protection, and centralized monitoring.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
2708
Module 7 · Advanced Domain 3 · Security anti-malware control Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2708), which action most directly controls the risk related to "anti-malware control"?

View answer choices
  1. Combine signatures, behavior analytics, updates, tamper protection, and centralized monitoring.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
2709
Module 7 · Advanced Domain 3 · Security anti-malware control Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2709), which action most directly controls the risk related to "anti-malware control"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Combine signatures, behavior analytics, updates, tamper protection, and centralized monitoring.
Practice
2710
Module 7 · Advanced Domain 3 · Security anti-malware control Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2710), which action most directly controls the risk related to "anti-malware control"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Combine signatures, behavior analytics, updates, tamper protection, and centralized monitoring.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
2711
Module 7 · Foundation Domain 3 · Security anti-malware control Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2711), which evidence best supports an assessment of "anti-malware control"?

View answer choices
  1. Detection telemetry showing engine, rule, object, action, and disposition.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
2712
Module 7 · Foundation Domain 3 · Security anti-malware control Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2712), which evidence best supports an assessment of "anti-malware control"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. Detection telemetry showing engine, rule, object, action, and disposition.
Practice
2713
Module 7 · Foundation Domain 3 · Security anti-malware control Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2713), which evidence best supports an assessment of "anti-malware control"?

View answer choices
  1. Detection telemetry showing engine, rule, object, action, and disposition.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. An architecture map showing which independent controls interrupt each attack path.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
2714
Module 7 · Applied Domain 3 · Security anti-malware control Unanswered

During a financial-services purple-team test (FIN-PT-M07-2714), which evidence best supports an assessment of "anti-malware control"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. Detection telemetry showing engine, rule, object, action, and disposition.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
2715
Module 7 · Applied Domain 3 · Security anti-malware control Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2715), which evidence best supports an assessment of "anti-malware control"?

View answer choices
  1. Detection telemetry showing engine, rule, object, action, and disposition.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
2716
Module 7 · Applied Domain 3 · Security anti-malware control Unanswered

During a government risk-validation project (GOV-RISK-M07-2716), which evidence best supports an assessment of "anti-malware control"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  3. A risk register with likelihood, impact, owner, treatment, and review date.
  4. Detection telemetry showing engine, rule, object, action, and disposition.
Practice
2717
Module 7 · Applied Domain 3 · Security anti-malware control Unanswered

During an e-commerce application review (ECOM-WEB-M07-2717), which evidence best supports an assessment of "anti-malware control"?

View answer choices
  1. Detection telemetry showing engine, rule, object, action, and disposition.
  2. An architecture map showing which independent controls interrupt each attack path.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. A risk register with likelihood, impact, owner, treatment, and review date.
Practice
2718
Module 7 · Advanced Domain 3 · Security anti-malware control Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2718), which evidence best supports an assessment of "anti-malware control"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. Detection telemetry showing engine, rule, object, action, and disposition.
  4. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
Practice
2719
Module 7 · Advanced Domain 3 · Security anti-malware control Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2719), which evidence best supports an assessment of "anti-malware control"?

View answer choices
  1. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. Detection telemetry showing engine, rule, object, action, and disposition.
  4. An architecture map showing which independent controls interrupt each attack path.
Practice
2720
Module 7 · Advanced Domain 3 · Security anti-malware control Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2720), which evidence best supports an assessment of "anti-malware control"?

View answer choices
  1. An architecture map showing which independent controls interrupt each attack path.
  2. A risk register with likelihood, impact, owner, treatment, and review date.
  3. A timeline linking alerts, decisions, evidence, containment, and recovery actions.
  4. Detection telemetry showing engine, rule, object, action, and disposition.
Practice
2721
Module 7 · Foundation Domain 3 · Security endpoint detection and response Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2721), which statement most accurately defines "endpoint detection and response"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  3. Endpoint telemetry and response capabilities used to identify, investigate, and contain malicious behavior.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
2722
Module 7 · Foundation Domain 3 · Security endpoint detection and response Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2722), which statement most accurately defines "endpoint detection and response"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Endpoint telemetry and response capabilities used to identify, investigate, and contain malicious behavior.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
2723
Module 7 · Foundation Domain 3 · Security endpoint detection and response Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2723), which statement most accurately defines "endpoint detection and response"?

View answer choices
  1. Endpoint telemetry and response capabilities used to identify, investigate, and contain malicious behavior.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
2724
Module 7 · Applied Domain 3 · Security endpoint detection and response Unanswered

During a financial-services purple-team test (FIN-PT-M07-2724), which statement most accurately defines "endpoint detection and response"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Endpoint telemetry and response capabilities used to identify, investigate, and contain malicious behavior.
Practice
2725
Module 7 · Applied Domain 3 · Security endpoint detection and response Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2725), which statement most accurately defines "endpoint detection and response"?

View answer choices
  1. Endpoint telemetry and response capabilities used to identify, investigate, and contain malicious behavior.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
2726
Module 7 · Applied Domain 3 · Security endpoint detection and response Unanswered

During a government risk-validation project (GOV-RISK-M07-2726), which statement most accurately defines "endpoint detection and response"?

View answer choices
  1. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  2. Endpoint telemetry and response capabilities used to identify, investigate, and contain malicious behavior.
  3. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  4. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
Practice
2727
Module 7 · Applied Domain 3 · Security endpoint detection and response Unanswered

During an e-commerce application review (ECOM-WEB-M07-2727), which statement most accurately defines "endpoint detection and response"?

View answer choices
  1. Endpoint telemetry and response capabilities used to identify, investigate, and contain malicious behavior.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
2728
Module 7 · Advanced Domain 3 · Security endpoint detection and response Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2728), which statement most accurately defines "endpoint detection and response"?

View answer choices
  1. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Endpoint telemetry and response capabilities used to identify, investigate, and contain malicious behavior.
Practice
2729
Module 7 · Advanced Domain 3 · Security endpoint detection and response Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2729), which statement most accurately defines "endpoint detection and response"?

View answer choices
  1. Endpoint telemetry and response capabilities used to identify, investigate, and contain malicious behavior.
  2. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  3. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
  4. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
Practice
2730
Module 7 · Advanced Domain 3 · Security endpoint detection and response Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2730), which statement most accurately defines "endpoint detection and response"?

View answer choices
  1. Endpoint telemetry and response capabilities used to identify, investigate, and contain malicious behavior.
  2. Identification and evaluation of threats, vulnerabilities, likelihood, and impact to support treatment decisions.
  3. Coordinated preparation, detection, analysis, containment, eradication, recovery, and improvement after incidents.
  4. Layering independent preventive, detective, and corrective controls so one failure is not decisive.
Practice
2731
Module 7 · Foundation Domain 3 · Security endpoint detection and response Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2731), which risk is most directly associated with "endpoint detection and response"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Signature-only protection may miss novel behavior and hands-on-keyboard activity.
  3. Controls chosen without risk context may protect low-value assets while critical risks remain.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
2732
Module 7 · Foundation Domain 3 · Security endpoint detection and response Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2732), which risk is most directly associated with "endpoint detection and response"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Signature-only protection may miss novel behavior and hands-on-keyboard activity.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
2733
Module 7 · Foundation Domain 3 · Security endpoint detection and response Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2733), which risk is most directly associated with "endpoint detection and response"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Signature-only protection may miss novel behavior and hands-on-keyboard activity.
Practice
2734
Module 7 · Applied Domain 3 · Security endpoint detection and response Unanswered

During a financial-services purple-team test (FIN-PT-M07-2734), which risk is most directly associated with "endpoint detection and response"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Signature-only protection may miss novel behavior and hands-on-keyboard activity.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
2735
Module 7 · Applied Domain 3 · Security endpoint detection and response Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2735), which risk is most directly associated with "endpoint detection and response"?

View answer choices
  1. Controls chosen without risk context may protect low-value assets while critical risks remain.
  2. Signature-only protection may miss novel behavior and hands-on-keyboard activity.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
2736
Module 7 · Applied Domain 3 · Security endpoint detection and response Unanswered

During a government risk-validation project (GOV-RISK-M07-2736), which risk is most directly associated with "endpoint detection and response"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Reliance on a single control creates a direct path when that control fails or is bypassed.
  3. Signature-only protection may miss novel behavior and hands-on-keyboard activity.
  4. Controls chosen without risk context may protect low-value assets while critical risks remain.
Practice
2737
Module 7 · Applied Domain 3 · Security endpoint detection and response Unanswered

During an e-commerce application review (ECOM-WEB-M07-2737), which risk is most directly associated with "endpoint detection and response"?

View answer choices
  1. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Reliance on a single control creates a direct path when that control fails or is bypassed.
  4. Signature-only protection may miss novel behavior and hands-on-keyboard activity.
Practice
2738
Module 7 · Advanced Domain 3 · Security endpoint detection and response Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2738), which risk is most directly associated with "endpoint detection and response"?

View answer choices
  1. Signature-only protection may miss novel behavior and hands-on-keyboard activity.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Reliance on a single control creates a direct path when that control fails or is bypassed.
Practice
2739
Module 7 · Advanced Domain 3 · Security endpoint detection and response Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2739), which risk is most directly associated with "endpoint detection and response"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Signature-only protection may miss novel behavior and hands-on-keyboard activity.
  4. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
Practice
2740
Module 7 · Advanced Domain 3 · Security endpoint detection and response Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2740), which risk is most directly associated with "endpoint detection and response"?

View answer choices
  1. Reliance on a single control creates a direct path when that control fails or is bypassed.
  2. Controls chosen without risk context may protect low-value assets while critical risks remain.
  3. Unplanned actions can destroy evidence, prolong compromise, or disrupt recovery.
  4. Signature-only protection may miss novel behavior and hands-on-keyboard activity.
Practice
2741
Module 7 · Foundation Domain 3 · Security endpoint detection and response Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2741), which action most directly controls the risk related to "endpoint detection and response"?

View answer choices
  1. Collect behavior telemetry, tune detections, isolate hosts, and preserve evidence.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
2742
Module 7 · Foundation Domain 3 · Security endpoint detection and response Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2742), which action most directly controls the risk related to "endpoint detection and response"?

View answer choices
  1. Design overlapping controls across identity, endpoint, network, application, and data layers.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Collect behavior telemetry, tune detections, isolate hosts, and preserve evidence.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
2743
Module 7 · Foundation Domain 3 · Security endpoint detection and response Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2743), which action most directly controls the risk related to "endpoint detection and response"?

View answer choices
  1. Collect behavior telemetry, tune detections, isolate hosts, and preserve evidence.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
2744
Module 7 · Applied Domain 3 · Security endpoint detection and response Unanswered

During a financial-services purple-team test (FIN-PT-M07-2744), which action most directly controls the risk related to "endpoint detection and response"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Collect behavior telemetry, tune detections, isolate hosts, and preserve evidence.
Practice
2745
Module 7 · Applied Domain 3 · Security endpoint detection and response Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2745), which action most directly controls the risk related to "endpoint detection and response"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Collect behavior telemetry, tune detections, isolate hosts, and preserve evidence.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
2746
Module 7 · Applied Domain 3 · Security endpoint detection and response Unanswered

During a government risk-validation project (GOV-RISK-M07-2746), which action most directly controls the risk related to "endpoint detection and response"?

View answer choices
  1. Maintain a repeatable assessment process tied to asset value and risk ownership.
  2. Collect behavior telemetry, tune detections, isolate hosts, and preserve evidence.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
Practice
2747
Module 7 · Applied Domain 3 · Security endpoint detection and response Unanswered

During an e-commerce application review (ECOM-WEB-M07-2747), which action most directly controls the risk related to "endpoint detection and response"?

View answer choices
  1. Collect behavior telemetry, tune detections, isolate hosts, and preserve evidence.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice
2748
Module 7 · Advanced Domain 3 · Security endpoint detection and response Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2748), which action most directly controls the risk related to "endpoint detection and response"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Maintain a repeatable assessment process tied to asset value and risk ownership.
  3. Design overlapping controls across identity, endpoint, network, application, and data layers.
  4. Collect behavior telemetry, tune detections, isolate hosts, and preserve evidence.
Practice
2749
Module 7 · Advanced Domain 3 · Security endpoint detection and response Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2749), which action most directly controls the risk related to "endpoint detection and response"?

View answer choices
  1. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  2. Design overlapping controls across identity, endpoint, network, application, and data layers.
  3. Collect behavior telemetry, tune detections, isolate hosts, and preserve evidence.
  4. Maintain a repeatable assessment process tied to asset value and risk ownership.
Practice
2750
Module 7 · Advanced Domain 3 · Security endpoint detection and response Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2750), which action most directly controls the risk related to "endpoint detection and response"?

View answer choices
  1. Collect behavior telemetry, tune detections, isolate hosts, and preserve evidence.
  2. Maintain tested playbooks, roles, communications, evidence handling, and exercises.
  3. Maintain a repeatable assessment process tied to asset value and risk ownership.
  4. Design overlapping controls across identity, endpoint, network, application, and data layers.
Practice