
EC-CouncilCertified Security Specialist
Domain 3Objective 1
Information Security Fundamentals ECSS Practice Questions (Page 7)
Part of the Ethical Hacking Fundamentals and Core Attacks domain, which makes up ~17% of our current practice bank.
50questions here
10free pages
10concepts
Questions 31–35
- 31
A government agency classifies a document as 'Secret'. According to the agency's data handling policy, Secret documents must be encrypted at rest, stored in a controlled access room, and only accessible to personnel with a specific clearance. An employee accidentally sends this document to an external partner without encryption. Which security goal has been most directly violated?
Select an answer first - 32
An organization's security team creates a document that specifies the exact encryption algorithms and key lengths that must be used for all data at rest. This document is best classified as a:
Select an answer first - 33
Which of the following documents defines the mandatory rules and expectations for acceptable use of an organization's IT resources?
Select an answer first - 34
A small business recently suffered a ransomware attack that encrypted all files on a shared drive. The investigation found that an employee clicked a link in a phishing email, which downloaded the malware. Which combination of threat, vulnerability, and control best describes this incident?
Select an answer first - 35
Which of the following is a common topic covered in security awareness training?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.