CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 2,851–2,900 of 5,000 matching questions

50 per page
2851
Module 7 · Foundation Domain 4 · Tools / Systems / Programs YARA Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2851), which risk is most directly associated with "YARA"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Overly broad rules create false positives while narrow rules miss variants.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
2852
Module 7 · Foundation Domain 4 · Tools / Systems / Programs YARA Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2852), which risk is most directly associated with "YARA"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Overly broad rules create false positives while narrow rules miss variants.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Automated modules can query third parties or collect data outside scope.
Practice
2853
Module 7 · Foundation Domain 4 · Tools / Systems / Programs YARA Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2853), which risk is most directly associated with "YARA"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Overly broad rules create false positives while narrow rules miss variants.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
2854
Module 7 · Applied Domain 4 · Tools / Systems / Programs YARA Unanswered

During a financial-services purple-team test (FIN-PT-M07-2854), which risk is most directly associated with "YARA"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Overly broad rules create false positives while narrow rules miss variants.
Practice
2855
Module 7 · Applied Domain 4 · Tools / Systems / Programs YARA Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2855), which risk is most directly associated with "YARA"?

View answer choices
  1. Overly broad rules create false positives while narrow rules miss variants.
  2. Automated modules can query third parties or collect data outside scope.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
2856
Module 7 · Applied Domain 4 · Tools / Systems / Programs YARA Unanswered

During a government risk-validation project (GOV-RISK-M07-2856), which risk is most directly associated with "YARA"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Overly broad rules create false positives while narrow rules miss variants.
  4. Automated modules can query third parties or collect data outside scope.
Practice
2857
Module 7 · Applied Domain 4 · Tools / Systems / Programs YARA Unanswered

During an e-commerce application review (ECOM-WEB-M07-2857), which risk is most directly associated with "YARA"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Overly broad rules create false positives while narrow rules miss variants.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
2858
Module 7 · Advanced Domain 4 · Tools / Systems / Programs YARA Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2858), which risk is most directly associated with "YARA"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Overly broad rules create false positives while narrow rules miss variants.
Practice
2859
Module 7 · Advanced Domain 4 · Tools / Systems / Programs YARA Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2859), which risk is most directly associated with "YARA"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Overly broad rules create false positives while narrow rules miss variants.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
2860
Module 7 · Advanced Domain 4 · Tools / Systems / Programs YARA Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2860), which risk is most directly associated with "YARA"?

View answer choices
  1. Exposed management services and old banners make vulnerable assets easy to discover.
  2. Overly broad rules create false positives while narrow rules miss variants.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Automated modules can query third parties or collect data outside scope.
Practice
2861
Module 7 · Foundation Domain 4 · Tools / Systems / Programs YARA Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2861), which action most directly controls the risk related to "YARA"?

View answer choices
  1. Combine stable characteristics, test against clean sets, and version rules.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
2862
Module 7 · Foundation Domain 4 · Tools / Systems / Programs YARA Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2862), which action most directly controls the risk related to "YARA"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Combine stable characteristics, test against clean sets, and version rules.
Practice
2863
Module 7 · Foundation Domain 4 · Tools / Systems / Programs YARA Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2863), which action most directly controls the risk related to "YARA"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Combine stable characteristics, test against clean sets, and version rules.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
2864
Module 7 · Applied Domain 4 · Tools / Systems / Programs YARA Unanswered

During a financial-services purple-team test (FIN-PT-M07-2864), which action most directly controls the risk related to "YARA"?

View answer choices
  1. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  2. Combine stable characteristics, test against clean sets, and version rules.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
2865
Module 7 · Applied Domain 4 · Tools / Systems / Programs YARA Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2865), which action most directly controls the risk related to "YARA"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Combine stable characteristics, test against clean sets, and version rules.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
2866
Module 7 · Applied Domain 4 · Tools / Systems / Programs YARA Unanswered

During a government risk-validation project (GOV-RISK-M07-2866), which action most directly controls the risk related to "YARA"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Combine stable characteristics, test against clean sets, and version rules.
Practice
2867
Module 7 · Applied Domain 4 · Tools / Systems / Programs YARA Unanswered

During an e-commerce application review (ECOM-WEB-M07-2867), which action most directly controls the risk related to "YARA"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Combine stable characteristics, test against clean sets, and version rules.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
2868
Module 7 · Advanced Domain 4 · Tools / Systems / Programs YARA Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2868), which action most directly controls the risk related to "YARA"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Combine stable characteristics, test against clean sets, and version rules.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
2869
Module 7 · Advanced Domain 4 · Tools / Systems / Programs YARA Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2869), which action most directly controls the risk related to "YARA"?

View answer choices
  1. Combine stable characteristics, test against clean sets, and version rules.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
2870
Module 7 · Advanced Domain 4 · Tools / Systems / Programs YARA Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2870), which action most directly controls the risk related to "YARA"?

View answer choices
  1. Combine stable characteristics, test against clean sets, and version rules.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
2871
Module 7 · Foundation Domain 4 · Tools / Systems / Programs YARA Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2871), which evidence best supports an assessment of "YARA"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A YARA match showing rule, strings, offsets, file hash, and analyst disposition.
Practice
2872
Module 7 · Foundation Domain 4 · Tools / Systems / Programs YARA Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2872), which evidence best supports an assessment of "YARA"?

View answer choices
  1. A YARA match showing rule, strings, offsets, file hash, and analyst disposition.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. Search results validated against the organization’s current external inventory.
  4. A relationship graph retaining sources and transformation history.
Practice
2873
Module 7 · Foundation Domain 4 · Tools / Systems / Programs YARA Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2873), which evidence best supports an assessment of "YARA"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. A YARA match showing rule, strings, offsets, file hash, and analyst disposition.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
2874
Module 7 · Applied Domain 4 · Tools / Systems / Programs YARA Unanswered

During a financial-services purple-team test (FIN-PT-M07-2874), which evidence best supports an assessment of "YARA"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. A relationship graph retaining sources and transformation history.
  3. A YARA match showing rule, strings, offsets, file hash, and analyst disposition.
  4. Search results validated against the organization’s current external inventory.
Practice
2875
Module 7 · Applied Domain 4 · Tools / Systems / Programs YARA Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2875), which evidence best supports an assessment of "YARA"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. Search results validated against the organization’s current external inventory.
  4. A YARA match showing rule, strings, offsets, file hash, and analyst disposition.
Practice
2876
Module 7 · Applied Domain 4 · Tools / Systems / Programs YARA Unanswered

During a government risk-validation project (GOV-RISK-M07-2876), which evidence best supports an assessment of "YARA"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. Search results validated against the organization’s current external inventory.
  3. A YARA match showing rule, strings, offsets, file hash, and analyst disposition.
  4. A relationship graph retaining sources and transformation history.
Practice
2877
Module 7 · Applied Domain 4 · Tools / Systems / Programs YARA Unanswered

During an e-commerce application review (ECOM-WEB-M07-2877), which evidence best supports an assessment of "YARA"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Search results validated against the organization’s current external inventory.
  3. A YARA match showing rule, strings, offsets, file hash, and analyst disposition.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
2878
Module 7 · Advanced Domain 4 · Tools / Systems / Programs YARA Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2878), which evidence best supports an assessment of "YARA"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. A relationship graph retaining sources and transformation history.
  3. A YARA match showing rule, strings, offsets, file hash, and analyst disposition.
  4. Search results validated against the organization’s current external inventory.
Practice
2879
Module 7 · Advanced Domain 4 · Tools / Systems / Programs YARA Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2879), which evidence best supports an assessment of "YARA"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. Search results validated against the organization’s current external inventory.
  3. A relationship graph retaining sources and transformation history.
  4. A YARA match showing rule, strings, offsets, file hash, and analyst disposition.
Practice
2880
Module 7 · Advanced Domain 4 · Tools / Systems / Programs YARA Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2880), which evidence best supports an assessment of "YARA"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. Search results validated against the organization’s current external inventory.
  3. A YARA match showing rule, strings, offsets, file hash, and analyst disposition.
  4. A relationship graph retaining sources and transformation history.
Practice
2881
Module 8 · Foundation Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During an authorized retail-company assessment (RET-LAB-M08-2881), which statement most accurately defines "network sniffing analysis"?

View answer choices
  1. Information gathering that directly interacts with target infrastructure or personnel.
  2. Inspection of captured traffic to understand protocols, conversations, and exposed data.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
2882
Module 8 · Foundation Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-2882), which statement most accurately defines "network sniffing analysis"?

View answer choices
  1. Inspection of captured traffic to understand protocols, conversations, and exposed data.
  2. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  3. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
2883
Module 8 · Foundation Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-2883), which statement most accurately defines "network sniffing analysis"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Inspection of captured traffic to understand protocols, conversations, and exposed data.
Practice
2884
Module 8 · Applied Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a financial-services purple-team test (FIN-PT-M08-2884), which statement most accurately defines "network sniffing analysis"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Inspection of captured traffic to understand protocols, conversations, and exposed data.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
2885
Module 8 · Applied Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-2885), which statement most accurately defines "network sniffing analysis"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Inspection of captured traffic to understand protocols, conversations, and exposed data.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
2886
Module 8 · Applied Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a government risk-validation project (GOV-RISK-M08-2886), which statement most accurately defines "network sniffing analysis"?

View answer choices
  1. Inspection of captured traffic to understand protocols, conversations, and exposed data.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Information gathering that directly interacts with target infrastructure or personnel.
Practice
2887
Module 8 · Applied Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During an e-commerce application review (ECOM-WEB-M08-2887), which statement most accurately defines "network sniffing analysis"?

View answer choices
  1. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  2. Information gathering that directly interacts with target infrastructure or personnel.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Inspection of captured traffic to understand protocols, conversations, and exposed data.
Practice
2888
Module 8 · Advanced Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a manufacturing and OT security review (MFG-OT-M08-2888), which statement most accurately defines "network sniffing analysis"?

View answer choices
  1. Inspection of captured traffic to understand protocols, conversations, and exposed data.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
Practice
2889
Module 8 · Advanced Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a mobile-services penetration test (MOB-TEST-M08-2889), which statement most accurately defines "network sniffing analysis"?

View answer choices
  1. Information gathering that directly interacts with target infrastructure or personnel.
  2. Inspection of captured traffic to understand protocols, conversations, and exposed data.
  3. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  4. Review of domain registration and registrar information to understand ownership and infrastructure clues.
Practice
2890
Module 8 · Advanced Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-2890), which statement most accurately defines "network sniffing analysis"?

View answer choices
  1. Analysis of DNS records and delegation to map names, services, mail, and infrastructure.
  2. Review of domain registration and registrar information to understand ownership and infrastructure clues.
  3. Information gathering that directly interacts with target infrastructure or personnel.
  4. Inspection of captured traffic to understand protocols, conversations, and exposed data.
Practice
2891
Module 8 · Foundation Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During an authorized retail-company assessment (RET-LAB-M08-2891), which risk is most directly associated with "network sniffing analysis"?

View answer choices
  1. Unencrypted traffic and unsafe protocols can leak credentials or sensitive information.
  2. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
2892
Module 8 · Foundation Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-2892), which risk is most directly associated with "network sniffing analysis"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Unencrypted traffic and unsafe protocols can leak credentials or sensitive information.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
2893
Module 8 · Foundation Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-2893), which risk is most directly associated with "network sniffing analysis"?

View answer choices
  1. Unencrypted traffic and unsafe protocols can leak credentials or sensitive information.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
Practice
2894
Module 8 · Applied Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a financial-services purple-team test (FIN-PT-M08-2894), which risk is most directly associated with "network sniffing analysis"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  3. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  4. Unencrypted traffic and unsafe protocols can leak credentials or sensitive information.
Practice
2895
Module 8 · Applied Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-2895), which risk is most directly associated with "network sniffing analysis"?

View answer choices
  1. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  2. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  3. Unencrypted traffic and unsafe protocols can leak credentials or sensitive information.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
2896
Module 8 · Applied Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a government risk-validation project (GOV-RISK-M08-2896), which risk is most directly associated with "network sniffing analysis"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Unencrypted traffic and unsafe protocols can leak credentials or sensitive information.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice
2897
Module 8 · Applied Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During an e-commerce application review (ECOM-WEB-M08-2897), which risk is most directly associated with "network sniffing analysis"?

View answer choices
  1. Unencrypted traffic and unsafe protocols can leak credentials or sensitive information.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  4. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
Practice
2898
Module 8 · Advanced Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a manufacturing and OT security review (MFG-OT-M08-2898), which risk is most directly associated with "network sniffing analysis"?

View answer choices
  1. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  4. Unencrypted traffic and unsafe protocols can leak credentials or sensitive information.
Practice
2899
Module 8 · Advanced Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a mobile-services penetration test (MOB-TEST-M08-2899), which risk is most directly associated with "network sniffing analysis"?

View answer choices
  1. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
  2. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  3. Unencrypted traffic and unsafe protocols can leak credentials or sensitive information.
  4. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
Practice
2900
Module 8 · Advanced Domain 2 · Analysis / Assessment network sniffing analysis Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-2900), which risk is most directly associated with "network sniffing analysis"?

View answer choices
  1. Overexposed records and unauthorized zone transfers can reveal internal naming and services.
  2. Direct probes can trigger defenses, affect services, or exceed authorized boundaries.
  3. Unencrypted traffic and unsafe protocols can leak credentials or sensitive information.
  4. Exposed registration details can support targeting, impersonation, or infrastructure mapping.
Practice