
EC-CouncilCertified Security Specialist
Domain 1Objective 1
Network Security Fundamentals ECSS Practice Questions (Page 1)
Part of the Network Defense Fundamentals and Controls domain, which makes up ~21% of our current practice bank.
50questions here
10free pages
8concepts
Questions 1–5
- 1
An employee receives an email that appears to be from the company's CEO, asking for a list of employee passwords. The email contains a link to a fake login page. Which type of threat is this, and what is the BEST immediate action for the employee?
Select an answer first - 2
A company's security policy requires that all network devices be configured to a secure baseline. The security team needs to document the exact configuration settings that must be applied. Which document should they create?
Select an answer first - 3
A company has a legacy application that requires a weak password policy because of hard-coded limitations. The application is critical to operations and cannot be replaced. Which compensating control would most effectively reduce the risk of credential-based attacks?
Select an answer first - 4
How do standards and procedures differ from a security policy?
Select an answer first - 5
A company has a policy that requires all software to be patched within 30 days of release. However, a critical business application is incompatible with the latest patch and crashes when the patch is applied. The security team must balance security and business continuity. Which approach is the BEST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.