Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilAssociate C|CISO

Domain 2Objective 1

Designing, Deploying, and Managing Security Controls ACCISO Practice Questions (Page 1)

Part of the Information Security Controls and Audit Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts

Questions 1–5

  1. 1expert · hard

    A company has implemented a security control that blocks all USB devices on employee workstations. The control is effective in preventing data exfiltration, but it has also blocked legitimate USB devices needed for presentations and other business tasks. The company wants to maintain security while allowing necessary USB use. What is the best approach?

    Select an answer first
  2. 2expert · hard

    A government agency has a security control that requires all employees to change their passwords every 30 days. The control is compliant with policy, but it has led to employees writing down passwords and an increase in help desk calls for password resets. The agency wants to maintain security while reducing these issues. What is the best approach?

    Select an answer first
  3. 3application · medium

    An e-commerce company is implementing a new payment processing system. The security team wants to ensure that customer payment data is protected even if the web server is compromised. The team also wants to deploy the system in a way that allows for testing before full production. Which approach best meets these requirements?

    Select an answer first
  4. 4application · medium

    A bank has implemented a new security information and event management (SIEM) system. After three months, the security operations center (SOC) analysts are overwhelmed by the number of alerts, many of which are false positives. The CISO wants to improve the efficiency of the SOC. What should be done?

    Select an answer first
  5. 5application · medium

    A company has implemented a new security control that requires all employees to complete annual security awareness training. After the first year, the security team wants to ensure that the training is effective and that employees are applying what they learned. What should the team do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.