
EC-CouncilAssociate C|CISO
Domain 4Objective 1
Access Controls ACCISO Practice Questions (Page 6)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
Questions 26–30
- 26
A security team is investigating a potential data breach. The audit logs show that a user's account was used to access a large number of files in a short period, but the user claims they did not perform the access. The team suspects the account may be compromised. Which action should the team take to preserve evidence while minimizing further risk?
Select an answer first - 27
A financial firm is preparing for an external audit. The audit will require evidence that user access rights are reviewed periodically and that terminated employees lose access promptly. Which combination of controls should the access governance team implement?
Select an answer first - 28
A security auditor is reviewing the access logs of a cloud storage service. The auditor notices that a service account has read access to a sensitive bucket, but the account's last activity was over six months ago. The auditor also finds that the service account is still listed as active in the identity provider. What should the auditor recommend?
Select an answer first - 29
In information security, what is the primary purpose of access control?
Select an answer first - 30
A multinational corporation must comply with data protection regulations that require access to personal data to be restricted based on the purpose of processing. The company has employees in different departments who need access to the same data for different purposes. For example, marketing needs access for campaign analysis, and support needs access for customer service. The access control system must enforce that employees only access data for their authorized purpose. Which access control model is best suited?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.