
EC-CouncilEthical Hacking Essentials
Domain 1Objective 4
Information Security Laws, Regulations, and Standards EHE Practice Questions (Page 5)
Part of the Information Security and Ethical Hacking Foundations domain, which makes up ~16% of our current practice bank.
46questions here
10free pages
4concepts
Questions 21–25
- 21
Which US federal agency publishes the Cybersecurity Framework (CSF) that provides voluntary guidance for organizations to manage and reduce cybersecurity risk?
Select an answer first - 22
An organization wants to implement a risk management process that is aligned with the NIST Cybersecurity Framework. Which sequence of functions best represents the core of the NIST CSF?
Select an answer first - 23
A European company's marketing team wants to send promotional emails to customers who signed up for a newsletter. The team has a list of email addresses collected from a previous campaign, but the customers were not told their data would be used for marketing. Under GDPR, what must the company do before sending the emails?
Select an answer first - 24
A company that processes credit card payments wants to ensure its network segmentation reduces the scope of PCI DSS compliance. Which approach is most effective?
Select an answer first - 25
An organization is implementing ISO/IEC 27001 and needs to define the scope of its ISMS. Which factor is most important to consider when defining the scope?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.