
EC-CouncilCertified Security Specialist
Domain 1Objective 3
Administrative Security Controls ECSS Practice Questions (Page 2)
Part of the Network Defense Fundamentals and Controls domain, which makes up ~21% of our current practice bank.
59questions here
12free pages
12concepts
Questions 6–10
- 6
The principle of least privilege means that users should be granted:
Select an answer first - 7
An organization is updating its security documentation. The security team needs a document that provides high-level direction on the acceptable use of company resources and states management's commitment to security. Which document type should be created?
Select an answer first - 8
A security administrator needs to apply a critical security patch to a production database server. The change management policy requires all changes to be approved by the change advisory board (CAB), but the next CAB meeting is in two weeks. The vulnerability is actively being exploited. What should the administrator do?
Select an answer first - 9
A company has just experienced a suspected data breach. The IT manager wants to ensure the incident is handled consistently and that evidence is preserved for potential legal action. Which action should be taken first?
Select an answer first - 10
A mid-sized company is formalizing its security program. The CISO wants to establish a governance framework that defines roles, responsibilities, and acceptable use expectations for all employees. Which administrative control should be implemented FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.