
EC-CouncilAssociate C|CISO
Domain 1Objective 2
Defining an Information Security Governance Program ACCISO Practice Questions (Page 9)
Part of the Governance, Risk, and Compliance domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)
59questions here
12free pages
12concepts
Questions 41–45
- 41
What is the primary purpose of information security governance?
Select an answer first - 42
A company's security governance program has been in place for two years. The board asks for evidence that the program is achieving its intended outcomes. Which combination of evidence would best demonstrate the five governance outcomes?
Select an answer first - 43
A bank's security governance committee wants to measure the effectiveness of its vulnerability management program. Which metric would best indicate performance?
Select an answer first - 44
Which statement correctly distinguishes information security governance from information security management?
Select an answer first - 45
A financial services firm's security governance committee wants to assess the effectiveness of its security awareness training program. Which metric would be most appropriate for this purpose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.