
EC-CouncilCertified Ethical Hacker
Domain 1Objective 7
Information Assurance and Risk Management CEH Practice Questions (Page 8)
Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 36–40
- 36
A company has identified a risk of a data breach due to weak authentication. The risk assessment shows a high likelihood and high impact. The company has a moderate risk appetite and a limited budget. Which combination of controls would be the most cost-effective to mitigate this risk?
Select an answer first - 37
Which risk treatment option involves taking action to reduce the likelihood or impact of a risk?
Select an answer first - 38
A multinational company is implementing a new security policy to comply with GDPR. The policy mandates that all personal data be encrypted at rest and in transit, and that access be logged. Which type of document is most appropriate to define the specific technical controls, such as the encryption algorithms and logging formats?
Select an answer first - 39
Which regulation is specifically designed to protect the personal data of individuals in the European Union?
Select an answer first - 40
Which risk assessment approach uses subjective ratings such as 'high', 'medium', and 'low' rather than monetary values?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.