
EC-CouncilNetwork Defense Essentials
Domain 2Objective 3
Security and Awareness Training NDE Practice Questions (Page 7)
Part of the Administrative and Physical Security Controls domain, which makes up ~15% of our current practice bank.
47questions here
10free pages
6concepts
Questions 31–35
- 31
A new manager asks why the company invests in security awareness training instead of just buying more security software. Which explanation best justifies the investment?
Select an answer first - 32
A company has completed a one-time security awareness training for all employees. Six months later, a new phishing technique starts circulating. What should the security team do to maintain effective defense?
Select an answer first - 33
After a year of mandatory security awareness training, the security team wants to evaluate whether the program is actually changing employee behavior. They have access to phishing simulation click rates, helpdesk reports of reported suspicious emails, and post-training quiz scores. Which combination of metrics provides the most reliable evidence of behavior change?
Select an answer first - 34
An organization has completed its initial security awareness training. The security team notices that phishing simulation click rates drop immediately after training but gradually rise over the following months. What should the team do to maintain the improvement?
Select an answer first - 35
What is the primary purpose of security awareness training in an organization?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.