
EC-CouncilCertified Security Specialist
Domain 1Objective 3
Administrative Security Controls ECSS Practice Questions (Page 9)
Part of the Network Defense Fundamentals and Controls domain, which makes up ~21% of our current practice bank.
59questions here
12free pages
12concepts
Questions 41–45
- 41
A company has a business continuity plan (BCP) that was tested successfully last year. Since then, the company has migrated several critical applications to a cloud provider and has hired a new IT team. The BCP has not been updated. What is the most important reason to update and retest the BCP?
Select an answer first - 42
A company has a high rate of employees falling for social engineering attacks, such as phishing emails and phone calls. The security team wants to implement a comprehensive security awareness program. Which two components are essential for an effective program? (Select all that apply.)
Select an answer first - 43
Which document would provide the exact steps to follow when granting a new user access to the network?
Select an answer first - 44
An online retailer that processes credit card payments wants to ensure it meets industry requirements for protecting cardholder data. The company already has a general security policy but needs to implement specific technical and operational requirements. Which control should the company adopt?
Select an answer first - 45
A system administrator needs to apply a critical security patch to a production server. The change management policy requires that all changes be reviewed and approved before implementation. However, the patch addresses a vulnerability that is actively being exploited. What should the administrator do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.