
EC-CouncilCertified Security Specialist
Domain 3Objective 1
Information Security Fundamentals ECSS Practice Questions (Page 8)
Part of the Ethical Hacking Fundamentals and Core Attacks domain, which makes up ~17% of our current practice bank.
50questions here
10free pages
10concepts
Questions 36–40
- 36
A government contractor stores documents classified as 'secret' and 'public' on the same file server. The contractor is required to protect secret documents from unauthorized disclosure while keeping public documents readily accessible. Which data handling approach best meets both requirements?
Select an answer first - 37
Why is security awareness training important for reducing human-related security risks?
Select an answer first - 38
Which phase of the incident response process involves limiting the scope and impact of a security incident?
Select an answer first - 39
A company has experienced several phishing incidents where employees clicked on malicious links in emails. The security team wants to reduce the likelihood of these incidents recurring. Which approach is most directly aimed at addressing the human factor?
Select an answer first - 40
A company's intrusion detection system (IDS) alerts on suspicious outbound traffic from a workstation. The security analyst investigates and confirms that the workstation is infected with malware that is exfiltrating data. The analyst isolates the workstation from the network and then runs an antivirus scan to remove the malware. Which two types of security controls did the analyst apply, in order?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.