
EC-CouncilAssociate C|CISO
Domain 1Objective 2
Defining an Information Security Governance Program ACCISO Practice Questions (Page 12)
Part of the Governance, Risk, and Compliance domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)
59questions here
12free pages
12concepts
Questions 56–59
- 56
A university is establishing a security governance committee. Which stakeholder group should be included to ensure that security decisions align with academic research needs?
Select an answer first - 57
A software company must decide between two security projects: implementing a data loss prevention (DLP) solution or enhancing the security of its CI/CD pipeline. The DLP solution is expensive and would protect customer data, while the CI/CD enhancement is cheaper and would prevent code tampering. The company has a strong revenue stream from its software products. Which decision best demonstrates value delivery?
Select an answer first - 58
A manufacturing company's security team is deploying a new firewall and updating intrusion detection rules. The board has approved the security budget and risk appetite. Which activity is an example of information security management, not governance?
Select an answer first - 59
A retail chain is planning to expand its e-commerce platform to support a new line of products. The CISO wants to ensure that security governance supports this business strategy. What is the most effective approach?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ACCISO
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.