Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilNetwork Defense Essentials

Domain 2Objective 2

Security Policies and Governance NDE Practice Questions (Page 4)

Part of the Administrative and Physical Security Controls domain, which makes up ~15% of our current practice bank.

49questions here
10free pages
6concepts

Questions 16–20

  1. 16expert · hard

    An organization's security policy requires that all servers be patched within 30 days of a vendor release. The IT team is struggling to meet this deadline because some legacy servers cannot be patched without causing application downtime. The team must find a way to comply with the policy while minimizing operational disruption. What should the team do?

    Select an answer first
  2. 17expert · hard

    A large enterprise has a security policy that mandates 'all remote access must use multi-factor authentication.' The security team is evaluating two solutions: one that uses a hardware token and one that uses a mobile app. The policy does not specify which method to use. The team needs to enforce a consistent standard across the organization. What should they do?

    Select an answer first
  3. 18expert · hard

    An organization's security policy requires that all laptops be encrypted. The IT team has deployed full-disk encryption, but some users have reported that their laptops are slow after the encryption was applied. The team must maintain the policy while addressing performance concerns. What should the team do?

    Select an answer first
  4. 19application · medium

    A multinational company is subject to the EU General Data Protection Regulation (GDPR) and must update its security policies. Which legal requirement must the policy explicitly address to remain compliant?

    Select an answer first
  5. 20expert · hard

    A cloud service provider hosts customer data and must comply with both GDPR and the customer's contractual requirements. The provider's security policy states that data will be encrypted at rest, but a customer requires that encryption keys be managed exclusively by the customer. The provider's current key management system gives the provider access to the keys. What should the provider do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.