
EC-CouncilSOC Essentials
Domain 1Objective 6
Information Security Standards, Laws, and Acts SCE Practice Questions (Page 5)
Part of the Computer Network and Security Fundamentals domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
4concepts
Questions 21–25
- 21
A company is implementing a new security policy and must align it with multiple frameworks and laws. The company is subject to ISO/IEC 27001, GDPR, and SOX. The security team is deciding how to structure the policy documentation. Which approach is most effective?
Select an answer first - 22
A company that processes credit card payments must comply with a standard that specifically addresses the security of cardholder data. Which standard is this?
Select an answer first - 23
An organization is implementing a security policy to comply with the GDPR. Which of the following policy elements is most directly required by GDPR?
Select an answer first - 24
A company that processes credit card transactions wants to reduce the scope of its PCI DSS compliance by isolating its cardholder data environment from the rest of the network. Which security control best supports this goal?
Select an answer first - 25
A multinational corporation is subject to GDPR, HIPAA, and PCI DSS. The security team is designing a single access control policy. Which approach best balances compliance with all three regulations?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.