
EC-CouncilCertified Security Specialist
Domain 1Objective 1
Network Security Fundamentals ECSS Practice Questions (Page 2)
Part of the Network Defense Fundamentals and Controls domain, which makes up ~21% of our current practice bank.
50questions here
10free pages
8concepts
Questions 6–10
- 6
A company's network was breached after an attacker exploited a known vulnerability in the web server software. The vulnerability had a patch available for three months before the breach. The security team also discovered that several user accounts still used the default password 'Welcome1'. Which two weaknesses MOST directly contributed to this breach?
Select an answer first - 7
A financial firm stores sensitive client data on a server. The security team wants to ensure that the data is not read by unauthorized parties and that it is not corrupted during transmission. Which combination of security goals and controls addresses these requirements?
Select an answer first - 8
A hospital's IT department wants to ensure that only authorized staff can access patient records, and that the records are not altered without authorization. Which security policy should the hospital implement to address BOTH of these requirements?
Select an answer first - 9
A company is designing its network security architecture. They want to ensure that if an attacker compromises a web server, the attacker cannot easily access the internal database server. Which defense-in-depth technique should they implement?
Select an answer first - 10
A security analyst is reviewing logs and notices that a user's account was used to log in from two different countries within 10 minutes. The analyst suspects a credential compromise. Which security goal is MOST directly threatened, and which control would BEST mitigate this risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.