Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilAssociate C|CISO

Domain 4Objective 1

Access Controls ACCISO Practice Questions (Page 2)

Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
6concepts

Questions 6–10

  1. 6application · medium

    A hospital is implementing an access control system for its electronic health record (EHR) application. Nurses need to view patient records for patients on their assigned ward, but only during their scheduled shift. Physicians need broader access to records for patients they are treating, and administrators need access only for audit purposes. The system must enforce these rules dynamically based on the user's current role, the patient's location, and the time of day. Which access control model best meets these requirements?

    Select an answer first
  2. 7application · medium

    A security analyst notices that a user's account has been logging in at unusual hours and accessing files outside their normal job function. The analyst suspects the account may be compromised. Which immediate action should the analyst take to limit potential damage?

    Select an answer first
  3. 8foundation · easy

    In a typical operating system, how is access control commonly implemented for files and directories?

    Select an answer first
  4. 9application · medium

    A company is implementing access control for a web application. They need to ensure that users can only access their own profile data and that administrators can access all profiles. The application uses a database to store user information. Which access control mechanism should be implemented at the application layer?

    Select an answer first
  5. 10application · medium

    A system administrator is configuring a Linux server that hosts a web application. The application needs to read a configuration file, but the application runs as a non-root user. The administrator wants to grant the application user read access to the file without giving the user any other permissions on the directory. Which mechanism should the administrator use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.