
EC-CouncilCertified Ethical Hacker
Domain 1Objective 6
MITRE ATT&CK Framework CEH Practice Questions (Page 7)
Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 31–35
- 31
A risk assessment team is using ATT&CK to identify gaps in their security posture. They have a coverage layer in ATT&CK Navigator and a list of techniques used by a threat group that targets their industry. Which of the following are valid steps in this gap analysis process? (Select all that apply.)
Select an answer first - 32
A security architect is conducting a gap analysis for a hybrid environment (on-premises Windows and Azure). They have a coverage layer in ATT&CK Navigator showing which techniques have detections. They also have a list of techniques used by a threat group that targets hybrid environments. Which approach would best identify the most critical gaps?
Select an answer first - 33
A threat intelligence analyst is trying to attribute an intrusion to a known adversary group. The intrusion used techniques that are common across many groups, such as spear-phishing and PowerShell. The analyst also found a rare technique: use of a specific USB-based attack. Which approach would best support attribution?
Select an answer first - 34
A security researcher is analyzing a malware sample that targets both Windows workstations and Android mobile devices. The researcher wants to document the techniques used by this malware in a structured format that covers both platforms. Which approach is most appropriate?
Select an answer first - 35
A security operations team wants to improve its detection coverage for a specific adversary group that is known to use PowerShell for reconnaissance and then exfiltrate data over HTTPS. The team uses a SIEM that can ingest Windows event logs and network flow data. Which approach best aligns their monitoring with the ATT&CK framework to detect this group's behavior?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.