
EC-CouncilCertified Security Specialist
Domain 3Objective 1
Information Security Fundamentals ECSS Practice Questions (Page 5)
Part of the Ethical Hacking Fundamentals and Core Attacks domain, which makes up ~17% of our current practice bank.
50questions here
10free pages
10concepts
Questions 21–25
- 21
A company is deploying a new VPN for remote employees. The security team wants to ensure that only employees with a valid company-issued certificate can connect, and that after connection, each employee can only access the file shares their department is allowed to see. Additionally, the team must be able to review a report of who connected and when. Which set of AAA components does this requirement map to?
Select an answer first - 22
A company's web server is compromised because the server was running an outdated version of the operating system with a known vulnerability. The attacker exploited this vulnerability to gain access and deface the website. Which combination of vulnerability and control would have most directly prevented this attack?
Select an answer first - 23
A hospital's patient portal allows patients to view their lab results online. The IT team is implementing a solution to ensure that only the patient and authorized clinicians can view the results, and that any attempt to access the results by an unauthorized user is logged and generates an alert. Which combination of security goals is the team primarily addressing?
Select an answer first - 24
Why is preparation an important phase in incident response?
Select an answer first - 25
An employee submits a large expense report and later claims they never submitted it. The finance system has a record of the submission, but the employee argues the record was fabricated. Which control would most directly prevent this dispute by proving the employee's action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.