
EC-CouncilCertified Ethical Hacker
Domain 1Objective 7
Information Assurance and Risk Management CEH Practice Questions (Page 3)
Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 11–15
- 11
Which document type is typically mandatory and specifies the exact steps to perform a task?
Select an answer first - 12
What is the primary purpose of a security policy in an organization?
Select an answer first - 13
A hospital is subject to HIPAA and is implementing a risk management plan. The security officer must ensure that all electronic protected health information (ePHI) is protected. Which control is most directly required by HIPAA's Security Rule?
Select an answer first - 14
Which standard is an internationally recognized framework for information security management systems (ISMS)?
Select an answer first - 15
An online banking application allows users to transfer funds. To ensure that a user cannot deny having initiated a transfer, the application should implement which control?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.