
EC-CouncilCertified Network Defender
Domain 7Objective 1
Risk Anticipation with Risk Management CND Practice Questions (Page 5)
Part of the Risk and Threat Management domain, which makes up ~16% of our current practice bank.
45questions here
9free pages
9concepts
Questions 21–25
- 21
What is the primary purpose of maintaining an asset inventory in risk identification?
Select an answer first - 22
A financial firm has implemented a risk treatment plan that includes regular patching and employee training. After a year, the firm's risk manager notices that the number of malware infections has decreased, but the number of phishing emails has increased. The risk manager is considering whether to update the risk assessment. Which action is most appropriate?
Select an answer first - 23
Which of the following is a widely recognized risk management framework used in cybersecurity?
Select an answer first - 24
A hospital has identified a risk of patient data breach due to unencrypted laptops. The risk assessment shows a high likelihood and high impact. The hospital has a limited budget and must choose between purchasing encryption software for all laptops (cost: $20,000) and purchasing cyber insurance (cost: $15,000/year). The hospital's risk tolerance is low. Which treatment option is most appropriate?
Select an answer first - 25
What is the purpose of reviewing risk management strategies over time?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.