
EC-CouncilEthical Hacking Essentials
Domain 1Objective 4
Information Security Laws, Regulations, and Standards EHE Practice Questions (Page 4)
Part of the Information Security and Ethical Hacking Foundations domain, which makes up ~16% of our current practice bank.
46questions here
10free pages
4concepts
Questions 16–20
- 16
A security analyst discovers that a contractor has been accessing customer records without authorization and selling the data to a third party. The organization is based in California. Which law is most directly applicable to this breach of customer data privacy?
Select an answer first - 17
Which international standard provides a framework for establishing, implementing, maintaining, and continually improving an information security management system (ISMS)?
Select an answer first - 18
Which US federal law is primarily intended to protect the privacy of students' educational records held by schools that receive federal funding?
Select an answer first - 19
Under the GDPR, what is the maximum timeframe within which an organization must notify the relevant supervisory authority of a personal data breach?
Select an answer first - 20
A penetration tester is hired by a company to test its external web application. During the test, the tester discovers a database containing customer credit card numbers. The tester's contract does not mention credit card data. What should the tester do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.