
EC-CouncilCertified Network Defender
Domain 3Objective 2
Data Security CND Practice Questions (Page 5)
Part of the Application and Data Security domain, which makes up ~10% of our current practice bank.
53questions here
11free pages
10concepts
Questions 21–25
- 21
A company is implementing a data classification policy and needs to decide how to handle data that is no longer actively used but must be retained for legal reasons. The data is stored on a file server and is classified as 'confidential'. The security team must ensure that the data is not accidentally modified or deleted, but it must be available for e-discovery if needed. Which approach is most appropriate?
Select an answer first - 22
A financial firm is building a test environment for a new application. The test data must be realistic but must not expose real customer personally identifiable information (PII). The firm also needs to track which test records correspond to which real customers for debugging. Which approach should the data team use?
Select an answer first - 23
What is the primary purpose of encrypting data at rest?
Select an answer first - 24
A company's DLP solution flags a large outbound email containing a spreadsheet with customer credit card numbers. The email is from the finance department to an external auditor. The DLP policy currently blocks all such emails. What should the administrator do to balance security and business needs?
Select an answer first - 25
A multinational company stores European customer data in a cloud region located in the EU. The company's support team in the United States needs to access this data for troubleshooting. Which practice best supports GDPR compliance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.