
EC-CouncilCertified Ethical Hacker
Domain 1Objective 7
Information Assurance and Risk Management CEH Practice Questions (Page 1)
Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 1–5
- 1
A security analyst is using the OCTAVE method to assess risks in a large enterprise. The analyst has identified critical assets and their associated threats. What is the next step in the OCTAVE process?
Select an answer first - 2
A government agency is required to follow NIST RMF for its information systems. The agency is also subject to FISMA compliance. During the 'Authorize' step of the RMF, what is the primary responsibility of the authorizing official?
Select an answer first - 3
A financial services firm has a critical trading application with an RTO of 15 minutes and an RPO of 5 minutes. The application runs on-premises. The firm is considering two disaster recovery options: (1) a hot standby site with synchronous replication, and (2) a cloud-based disaster recovery service with asynchronous replication. The cloud service is significantly cheaper but has a recovery time of 30 minutes. The firm's risk appetite is low, and the board has mandated that no single point of failure should cause a regulatory breach. What is the most appropriate decision?
Select an answer first - 4
A company is developing a new security policy for remote work. The policy must align with ISO 27001 and ensure that employees use VPN for all remote access. Which document should be created first to define the high-level security objectives and management commitment?
Select an answer first - 5
A regional bank is assessing the risk of a new mobile banking feature. The security team estimates that a successful account takeover could cause a financial loss of $2,000,000, and the likelihood of occurrence in the next year is 5%. The bank's risk appetite allows accepting risks with an annualized loss expectancy (ALE) below $50,000. What should the bank do with this risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.