
EC-CouncilCertified Security Specialist
Domain 1Objective 7
Data Security ECSS Practice Questions (Page 7)
Part of the Network Defense Fundamentals and Controls domain, which makes up ~21% of our current practice bank.
53questions here
11free pages
10concepts
Questions 31–35
- 31
A company must comply with a regulation that requires retaining customer transaction data for five years. The company also has a data minimization policy that requires deleting data that is no longer needed. After five years, what should the company do with the transaction data?
Select an answer first - 32
Which of the following is a typical capability of a Data Loss Prevention (DLP) solution?
Select an answer first - 33
What is the main purpose of a data retention policy?
Select an answer first - 34
A healthcare organization stores patient records in an on-premises SQL database and also transmits them to a cloud-based analytics platform for research. The compliance team requires that patient data remain unreadable if the database file is stolen, and that the data be protected while moving to the cloud. Which combination of controls should the security team implement?
Select an answer first - 35
A global company processes personal data of users in multiple jurisdictions. The company wants to implement a single data protection policy that satisfies the strictest requirements. What is the most effective approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.