
EC-CouncilCertified Network Defender
Domain 7Objective 1
Risk Anticipation with Risk Management CND Practice Questions (Page 4)
Part of the Risk and Threat Management domain, which makes up ~16% of our current practice bank.
45questions here
9free pages
9concepts
Questions 16–20
- 16
What is the purpose of risk evaluation?
Select an answer first - 17
Which method is commonly used to identify potential risks to organizational assets?
Select an answer first - 18
When an organization decides to purchase cybersecurity insurance, which risk treatment option are they applying?
Select an answer first - 19
A network defender has completed a risk assessment for a new cloud-based application. The assessment identified a risk of unauthorized access to customer data due to weak authentication. The likelihood is moderate, and the impact is high. The organization's risk criteria state that any risk with a high impact must be treated, regardless of likelihood. The defender is considering two treatment options: implementing multi-factor authentication (MFA) at a cost of $20,000, or purchasing cyber insurance at a cost of $10,000 per year. Which option is most appropriate?
Select an answer first - 20
Which risk treatment option involves implementing controls to reduce the likelihood or impact of a risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.