
EC-CouncilCertified Network Defender
Domain 3Objective 2
Data Security CND Practice Questions (Page 7)
Part of the Application and Data Security domain, which makes up ~10% of our current practice bank.
53questions here
11free pages
10concepts
Questions 31–35
- 31
A hospital is required by law to retain patient medical records for 10 years after the last treatment. After that period, the records must be securely destroyed. The hospital stores records in an electronic health record (EHR) system and also has backup tapes. Which disposal method is most appropriate for the backup tapes?
Select an answer first - 32
A company's DLP solution is generating a high number of false positives, causing employees to ignore DLP alerts. The security team wants to reduce false positives without significantly increasing the risk of data exfiltration. Which approach is most effective?
Select an answer first - 33
A company's backup strategy uses a 3-2-1 rule: three copies of data, on two different media types, with one copy offsite. The company currently has the primary data on a SAN, a backup on tape, and a backup in a cloud storage bucket. Which additional control is most important to ensure the backups are usable in a disaster?
Select an answer first - 34
Which regulation specifically governs the protection of health information in the United States?
Select an answer first - 35
What is the primary purpose of a data retention policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.