
EC-CouncilEthical Hacking Essentials
Domain 1Objective 1
Overview of Information Security and Defense Strategies EHE Practice Questions (Page 4)
Part of the Information Security and Ethical Hacking Foundations domain, which makes up ~16% of our current practice bank.
50questions here
10free pages
7concepts
Questions 16–20
- 16
What is the first step in the risk management process?
Select an answer first - 17
After a security breach, an organization restores systems from backups and applies patches to close the exploited vulnerability. Which category of security control does this represent?
Select an answer first - 18
What is the primary purpose of a defense-in-depth strategy?
Select an answer first - 19
A company has a web server that is vulnerable to SQL injection. The company has implemented a web application firewall (WAF) that blocks many SQL injection attempts. However, the WAF is not foolproof, and the company wants to reduce the risk further. Which action would be most effective?
Select an answer first - 20
A hospital's patient portal stores sensitive health records. A recent vulnerability scan revealed that the web application is susceptible to SQL injection, and the IT team has not yet applied the vendor's security patch. Which combination of controls best reduces the immediate risk while the patch is being tested?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.