
EC-CouncilAssociate C|CISO
Domain 2Objective 1
Designing, Deploying, and Managing Security Controls ACCISO Practice Questions (Page 4)
Part of the Information Security Controls and Audit Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 16–20
- 16
A company is implementing a new access control system for its data center. The security team wants to ensure that only authorized personnel can enter the server room, and that access is logged and reviewed. Which combination of controls and lifecycle activities should be implemented?
Select an answer first - 17
What is the primary purpose of assessing the effectiveness of security controls?
Select an answer first - 18
Which deployment strategy for security controls involves implementing controls in stages across different business units or locations over time?
Select an answer first - 19
A software development company is implementing a new access control policy for its source code repository. The CISO wants to ensure that developers can only access the code they need for their current projects, and that access is reviewed regularly. Which combination of principles and practices should be applied?
Select an answer first - 20
A company has implemented a security control that restricts access to sensitive files based on the user's job role. The control is effective, but it has caused delays because employees sometimes need temporary access to files outside their role for special projects. The company wants to maintain security while enabling these temporary needs. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.