Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Network Defender

Domain 7Objective 1

Risk Anticipation with Risk Management CND Practice Questions (Page 7)

Part of the Risk and Threat Management domain, which makes up ~16% of our current practice bank.

45questions here
9free pages
9concepts

Questions 31–35

  1. 31application · medium

    A regional bank is conducting a risk assessment for its new mobile banking application. The security team has identified a vulnerability in the third-party payment API that could allow unauthorized transactions. The team estimates the vulnerability has a 20% chance of being exploited in the next year, and if exploited, the financial loss would be $500,000. The bank's risk tolerance threshold for high-impact risks is $100,000. Which action should the team take first?

    Select an answer first
  2. 32expert · hard

    A network defender has implemented a risk treatment plan to reduce the risk of phishing attacks by deploying email filtering and conducting security awareness training. After six months, the defender wants to evaluate the effectiveness of the treatment. The defender has collected data on the number of phishing emails that reached users' inboxes and the number of users who clicked on a phishing link. What is the most appropriate way to evaluate the effectiveness?

    Select an answer first
  3. 33foundation · easy

    What is the primary purpose of documenting the risk management process?

    Select an answer first
  4. 34application · medium

    A university has a risk of student data exposure due to a misconfigured cloud storage. The risk assessment shows a likelihood of 3 (moderate) and an impact of 4 (major) on a 5-point scale. The university's risk criteria state that any risk with a score of 12 or higher requires treatment. What should the university do?

    Select an answer first
  5. 35application · medium

    A network defender has completed a risk assessment for a new cloud-based customer relationship management (CRM) system. The assessment identified a high-risk vulnerability in the CRM's authentication mechanism. The defender needs to communicate this risk to the executive team, who are not technical. What is the most effective way to communicate this risk?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.