
EC-CouncilNetwork Defense Essentials
Domain 2Objective 3
Security and Awareness Training NDE Practice Questions (Page 1)
Part of the Administrative and Physical Security Controls domain, which makes up ~15% of our current practice bank.
47questions here
10free pages
6concepts
Questions 1–5
- 1
An organization's security team wants to evaluate whether its simulated phishing campaign is improving employee vigilance over time. Which approach would provide the most meaningful measurement?
Select an answer first - 2
A security team is evaluating the effectiveness of its training program. They have data on quiz scores, completion rates, and phishing simulation click rates. Which data point is the most reliable indicator of whether employees will apply training in real situations?
Select an answer first - 3
A global company must deliver security awareness training to employees in different regions and time zones. Some regions have strict data privacy laws that restrict the use of third-party training platforms. The training must include phishing simulations and be measurable. Which approach best balances these constraints?
Select an answer first - 4
Which group is primarily responsible for designing and delivering security awareness training programs?
Select an answer first - 5
A security team is designing a training program for a company that handles highly sensitive data. They have a limited budget and must choose between (a) annual in-depth training for all employees, or (b) quarterly short refresher courses with targeted content. Which approach is more likely to maintain a high level of awareness?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.