
EC-CouncilEthical Hacking Essentials
Domain 1Objective 1
Overview of Information Security and Defense Strategies EHE Practice Questions (Page 10)
Part of the Information Security and Ethical Hacking Foundations domain, which makes up ~16% of our current practice bank.
50questions here
10free pages
7concepts
Questions 46–50
- 46
A company has a mature security program with preventive controls such as firewalls and endpoint protection. However, a recent audit found that the company has no formal incident response plan and no backup restoration testing. The audit recommends adding detective and corrective controls. Which control should be implemented first to improve the company's security posture?
Select an answer first - 47
Which of the following is an example of implementing defense in depth?
Select an answer first - 48
After a data breach, the security team restores the affected systems from backups and applies patches to close the vulnerability. Which type of security control is the team performing?
Select an answer first - 49
A security team is designing a defense-in-depth strategy for a new application. They have implemented a web application firewall (WAF), strong authentication, and encryption. Which additional control would best complete a layered defense by addressing the detection gap?
Select an answer first - 50
Why are security policies important to an organization's defense strategy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to EHE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.