CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 3,001–3,050 of 5,000 matching questions

50 per page
3001
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During an authorized retail-company assessment (RET-LAB-M08-3001), which statement most accurately defines "Wireshark"?

View answer choices
  1. A graphical protocol analyzer used to capture, decode, filter, and inspect network traffic.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
3002
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-3002), which statement most accurately defines "Wireshark"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A graphical protocol analyzer used to capture, decode, filter, and inspect network traffic.
Practice
3003
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-3003), which statement most accurately defines "Wireshark"?

View answer choices
  1. A graphical protocol analyzer used to capture, decode, filter, and inspect network traffic.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
3004
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a financial-services purple-team test (FIN-PT-M08-3004), which statement most accurately defines "Wireshark"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A graphical protocol analyzer used to capture, decode, filter, and inspect network traffic.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
3005
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-3005), which statement most accurately defines "Wireshark"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A graphical protocol analyzer used to capture, decode, filter, and inspect network traffic.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
3006
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a government risk-validation project (GOV-RISK-M08-3006), which statement most accurately defines "Wireshark"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A graphical protocol analyzer used to capture, decode, filter, and inspect network traffic.
Practice
3007
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During an e-commerce application review (ECOM-WEB-M08-3007), which statement most accurately defines "Wireshark"?

View answer choices
  1. A graphical protocol analyzer used to capture, decode, filter, and inspect network traffic.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
3008
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a manufacturing and OT security review (MFG-OT-M08-3008), which statement most accurately defines "Wireshark"?

View answer choices
  1. A search service that indexes Internet-connected devices and service banners.
  2. A graphical protocol analyzer used to capture, decode, filter, and inspect network traffic.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
3009
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a mobile-services penetration test (MOB-TEST-M08-3009), which statement most accurately defines "Wireshark"?

View answer choices
  1. A graphical protocol analyzer used to capture, decode, filter, and inspect network traffic.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
3010
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-3010), which statement most accurately defines "Wireshark"?

View answer choices
  1. A graphical protocol analyzer used to capture, decode, filter, and inspect network traffic.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A modular reconnaissance framework used to organize authorized OSINT collection.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
3011
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During an authorized retail-company assessment (RET-LAB-M08-3011), which risk is most directly associated with "Wireshark"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Automated modules can query third parties or collect data outside scope.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Captures can contain credentials, personal data, and other sensitive content.
Practice
3012
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-3012), which risk is most directly associated with "Wireshark"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Captures can contain credentials, personal data, and other sensitive content.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3013
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-3013), which risk is most directly associated with "Wireshark"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Captures can contain credentials, personal data, and other sensitive content.
  4. Automated modules can query third parties or collect data outside scope.
Practice
3014
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a financial-services purple-team test (FIN-PT-M08-3014), which risk is most directly associated with "Wireshark"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Captures can contain credentials, personal data, and other sensitive content.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3015
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-3015), which risk is most directly associated with "Wireshark"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Captures can contain credentials, personal data, and other sensitive content.
Practice
3016
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a government risk-validation project (GOV-RISK-M08-3016), which risk is most directly associated with "Wireshark"?

View answer choices
  1. Captures can contain credentials, personal data, and other sensitive content.
  2. Automated modules can query third parties or collect data outside scope.
  3. Exposed management services and old banners make vulnerable assets easy to discover.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3017
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During an e-commerce application review (ECOM-WEB-M08-3017), which risk is most directly associated with "Wireshark"?

View answer choices
  1. Combining public data can expose relationships that were not obvious individually.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Captures can contain credentials, personal data, and other sensitive content.
  4. Automated modules can query third parties or collect data outside scope.
Practice
3018
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a manufacturing and OT security review (MFG-OT-M08-3018), which risk is most directly associated with "Wireshark"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Combining public data can expose relationships that were not obvious individually.
  3. Captures can contain credentials, personal data, and other sensitive content.
  4. Exposed management services and old banners make vulnerable assets easy to discover.
Practice
3019
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a mobile-services penetration test (MOB-TEST-M08-3019), which risk is most directly associated with "Wireshark"?

View answer choices
  1. Automated modules can query third parties or collect data outside scope.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Combining public data can expose relationships that were not obvious individually.
  4. Captures can contain credentials, personal data, and other sensitive content.
Practice
3020
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-3020), which risk is most directly associated with "Wireshark"?

View answer choices
  1. Captures can contain credentials, personal data, and other sensitive content.
  2. Exposed management services and old banners make vulnerable assets easy to discover.
  3. Automated modules can query third parties or collect data outside scope.
  4. Combining public data can expose relationships that were not obvious individually.
Practice
3021
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During an authorized retail-company assessment (RET-LAB-M08-3021), which action most directly controls the risk related to "Wireshark"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Limit capture scope, protect files, and use display filters for focused analysis.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3022
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-3022), which action most directly controls the risk related to "Wireshark"?

View answer choices
  1. Limit capture scope, protect files, and use display filters for focused analysis.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3023
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-3023), which action most directly controls the risk related to "Wireshark"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Limit capture scope, protect files, and use display filters for focused analysis.
Practice
3024
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a financial-services purple-team test (FIN-PT-M08-3024), which action most directly controls the risk related to "Wireshark"?

View answer choices
  1. Limit capture scope, protect files, and use display filters for focused analysis.
  2. Configure workspaces, API keys, modules, and scope before collection.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3025
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-3025), which action most directly controls the risk related to "Wireshark"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Limit capture scope, protect files, and use display filters for focused analysis.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3026
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a government risk-validation project (GOV-RISK-M08-3026), which action most directly controls the risk related to "Wireshark"?

View answer choices
  1. Limit capture scope, protect files, and use display filters for focused analysis.
  2. Minimize public leakage and review graph results for source quality and authorization.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
Practice
3027
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During an e-commerce application review (ECOM-WEB-M08-3027), which action most directly controls the risk related to "Wireshark"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Configure workspaces, API keys, modules, and scope before collection.
  4. Limit capture scope, protect files, and use display filters for focused analysis.
Practice
3028
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a manufacturing and OT security review (MFG-OT-M08-3028), which action most directly controls the risk related to "Wireshark"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Limit capture scope, protect files, and use display filters for focused analysis.
  4. Minimize public leakage and review graph results for source quality and authorization.
Practice
3029
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a mobile-services penetration test (MOB-TEST-M08-3029), which action most directly controls the risk related to "Wireshark"?

View answer choices
  1. Minimize public leakage and review graph results for source quality and authorization.
  2. Limit capture scope, protect files, and use display filters for focused analysis.
  3. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  4. Configure workspaces, API keys, modules, and scope before collection.
Practice
3030
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-3030), which action most directly controls the risk related to "Wireshark"?

View answer choices
  1. Configure workspaces, API keys, modules, and scope before collection.
  2. Maintain external asset inventory and restrict or remove unnecessary Internet exposure.
  3. Minimize public leakage and review graph results for source quality and authorization.
  4. Limit capture scope, protect files, and use display filters for focused analysis.
Practice
3031
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During an authorized retail-company assessment (RET-LAB-M08-3031), which evidence best supports an assessment of "Wireshark"?

View answer choices
  1. A saved capture with a documented filter and decoded protocol evidence.
  2. A relationship graph retaining sources and transformation history.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Search results validated against the organization’s current external inventory.
Practice
3032
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-3032), which evidence best supports an assessment of "Wireshark"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. A saved capture with a documented filter and decoded protocol evidence.
  3. Search results validated against the organization’s current external inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
3033
Module 8 · Foundation Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-3033), which evidence best supports an assessment of "Wireshark"?

View answer choices
  1. A saved capture with a documented filter and decoded protocol evidence.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A relationship graph retaining sources and transformation history.
Practice
3034
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a financial-services purple-team test (FIN-PT-M08-3034), which evidence best supports an assessment of "Wireshark"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. Search results validated against the organization’s current external inventory.
  3. A relationship graph retaining sources and transformation history.
  4. A saved capture with a documented filter and decoded protocol evidence.
Practice
3035
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-3035), which evidence best supports an assessment of "Wireshark"?

View answer choices
  1. Workspace data showing module, source, timestamp, and scoped target.
  2. A relationship graph retaining sources and transformation history.
  3. A saved capture with a documented filter and decoded protocol evidence.
  4. Search results validated against the organization’s current external inventory.
Practice
3036
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a government risk-validation project (GOV-RISK-M08-3036), which evidence best supports an assessment of "Wireshark"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. A saved capture with a documented filter and decoded protocol evidence.
  3. Search results validated against the organization’s current external inventory.
  4. Workspace data showing module, source, timestamp, and scoped target.
Practice
3037
Module 8 · Applied Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During an e-commerce application review (ECOM-WEB-M08-3037), which evidence best supports an assessment of "Wireshark"?

View answer choices
  1. A saved capture with a documented filter and decoded protocol evidence.
  2. Search results validated against the organization’s current external inventory.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. A relationship graph retaining sources and transformation history.
Practice
3038
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a manufacturing and OT security review (MFG-OT-M08-3038), which evidence best supports an assessment of "Wireshark"?

View answer choices
  1. A relationship graph retaining sources and transformation history.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. Search results validated against the organization’s current external inventory.
  4. A saved capture with a documented filter and decoded protocol evidence.
Practice
3039
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a mobile-services penetration test (MOB-TEST-M08-3039), which evidence best supports an assessment of "Wireshark"?

View answer choices
  1. A saved capture with a documented filter and decoded protocol evidence.
  2. A relationship graph retaining sources and transformation history.
  3. Workspace data showing module, source, timestamp, and scoped target.
  4. Search results validated against the organization’s current external inventory.
Practice
3040
Module 8 · Advanced Domain 4 · Tools / Systems / Programs Wireshark Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-3040), which evidence best supports an assessment of "Wireshark"?

View answer choices
  1. A saved capture with a documented filter and decoded protocol evidence.
  2. Workspace data showing module, source, timestamp, and scoped target.
  3. Search results validated against the organization’s current external inventory.
  4. A relationship graph retaining sources and transformation history.
Practice
3041
Module 8 · Foundation Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During an authorized retail-company assessment (RET-LAB-M08-3041), which statement most accurately defines "tcpdump"?

View answer choices
  1. A search service that indexes Internet-connected devices and service banners.
  2. A command-line packet capture and filtering utility based on libpcap.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
3042
Module 8 · Foundation Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a hospital incident-response exercise (HLT-SOC-M08-3042), which statement most accurately defines "tcpdump"?

View answer choices
  1. A command-line packet capture and filtering utility based on libpcap.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
3043
Module 8 · Foundation Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a university cyber-range engagement (EDU-RANGE-M08-3043), which statement most accurately defines "tcpdump"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A command-line packet capture and filtering utility based on libpcap.
Practice
3044
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a financial-services purple-team test (FIN-PT-M08-3044), which statement most accurately defines "tcpdump"?

View answer choices
  1. A command-line packet capture and filtering utility based on libpcap.
  2. A modular reconnaissance framework used to organize authorized OSINT collection.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
3045
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a cloud startup security audit (CLD-AUDIT-M08-3045), which statement most accurately defines "tcpdump"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A command-line packet capture and filtering utility based on libpcap.
  3. A search service that indexes Internet-connected devices and service banners.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
3046
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a government risk-validation project (GOV-RISK-M08-3046), which statement most accurately defines "tcpdump"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  3. A command-line packet capture and filtering utility based on libpcap.
  4. A search service that indexes Internet-connected devices and service banners.
Practice
3047
Module 8 · Applied Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During an e-commerce application review (ECOM-WEB-M08-3047), which statement most accurately defines "tcpdump"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A command-line packet capture and filtering utility based on libpcap.
Practice
3048
Module 8 · Advanced Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a manufacturing and OT security review (MFG-OT-M08-3048), which statement most accurately defines "tcpdump"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A command-line packet capture and filtering utility based on libpcap.
  4. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
Practice
3049
Module 8 · Advanced Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a mobile-services penetration test (MOB-TEST-M08-3049), which statement most accurately defines "tcpdump"?

View answer choices
  1. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A command-line packet capture and filtering utility based on libpcap.
  4. A modular reconnaissance framework used to organize authorized OSINT collection.
Practice
3050
Module 8 · Advanced Domain 4 · Tools / Systems / Programs tcpdump Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M08-3050), which statement most accurately defines "tcpdump"?

View answer choices
  1. A modular reconnaissance framework used to organize authorized OSINT collection.
  2. A search service that indexes Internet-connected devices and service banners.
  3. A link-analysis platform for visualizing relationships among people, domains, organizations, and infrastructure.
  4. A command-line packet capture and filtering utility based on libpcap.
Practice