
EC-CouncilNetwork Defense Essentials
Domain 2Objective 3
Security and Awareness Training NDE Practice Questions (Page 2)
Part of the Administrative and Physical Security Controls domain, which makes up ~15% of our current practice bank.
47questions here
10free pages
6concepts
Questions 6–10
- 6
A small company with 30 employees wants to improve its phishing resistance. The budget is limited, and the security team has no dedicated training platform. Which approach is the most cost-effective and still provides measurable results?
Select an answer first - 7
A company has employees who are geographically dispersed and work remotely. The security team needs to deliver training that is consistent across all locations and can be tracked for compliance. Which delivery method is most suitable?
Select an answer first - 8
What is the best way to evaluate whether security awareness training has changed employee behavior?
Select an answer first - 9
After a simulated phishing campaign, the security team finds that the click rate is 15%, but the helpdesk also reports a 40% increase in employees forwarding suspicious emails for verification. How should the team interpret these results?
Select an answer first - 10
A mid-sized company recently suffered a ransomware infection after an employee clicked a link in a phishing email. The security team must roll out a training program that reaches all 500 employees across multiple shifts and locations, including remote workers. The program must include realistic phishing simulations and provide measurable data on who is clicking. Which training delivery method best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.