
EC-CouncilCertified Ethical Hacker
Domain 1Objective 9
Compliance Standards (PCI DSS, HIPAA, GDPR) CEH Practice Questions (Page 9)
Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
12concepts
Questions 41–44
- 41
Which of the following GDPR violations would likely result in the lower tier of fines (up to €10 million or 2% of global annual turnover)?
Select an answer first - 42
A healthcare organization operates a patient portal that allows patients to pay their medical bills online using credit cards. The portal stores both payment card data and patients' medical records. The organization is subject to both HIPAA and PCI DSS. Which statement accurately describes how the organization should approach compliance?
Select an answer first - 43
An EU citizen discovers that a social media platform is processing their personal data for targeted advertising without their consent. The individual wants to prevent the platform from using their data for this purpose. Which GDPR right is the individual exercising?
Select an answer first - 44
A regional healthcare clinic processes credit card payments for patient co-pays and also stores electronic health records (EHRs) that include patient names and diagnoses. The clinic wants to ensure it meets the applicable compliance requirements for both types of data. Which combination of standards must the clinic address?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CEH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.