
EC-CouncilCertified Security Specialist
Domain 1Objective 7
Data Security ECSS Practice Questions (Page 4)
Part of the Network Defense Fundamentals and Controls domain, which makes up ~21% of our current practice bank.
53questions here
11free pages
10concepts
Questions 16–20
- 16
An e-commerce company operating in the European Union collects customer data for order processing. They also share some data with a payment processor in the United States. What must the company ensure to comply with GDPR requirements for international data transfers?
Select an answer first - 17
Which access control model assigns permissions based on the roles that users have within an organization?
Select an answer first - 18
A security analyst needs to verify that a configuration file has not been tampered with since it was last approved. The analyst has the original hash value of the file. What should the analyst do?
Select an answer first - 19
What is the primary purpose of encrypting data at rest?
Select an answer first - 20
An organization processes credit card payments. To comply with PCI DSS, the organization must protect cardholder data. Which approach provides the strongest protection for data while it is being processed in memory?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.