
EC-CouncilCertified Ethical Hacker
Domain 1Objective 9
Compliance Standards (PCI DSS, HIPAA, GDPR) CEH Practice Questions (Page 2)
Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
12concepts
Questions 6–10
- 6
Under the GDPR, when is a Data Protection Impact Assessment (DPIA) required?
Select an answer first - 7
An EU resident submits a request to a social media platform to delete all personal data the platform has collected about them. The platform uses the data for targeted advertising and also shares it with third-party data brokers. Under GDPR, which of the following actions must the platform take? (Select all that apply.)
Select an answer first - 8
Under the HIPAA Security Rule, which of the following is a technical safeguard?
Select an answer first - 9
What is the primary purpose of the Health Insurance Portability and Accountability Act (HIPAA)?
Select an answer first - 10
An EU data subject requests that a social media platform rectify inaccurate personal data. The platform believes the data is accurate and refuses the request. The data subject then files a complaint with the supervisory authority. What is the supervisory authority likely to do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.