Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilAssociate C|CISO

Domain 2Objective 1

Designing, Deploying, and Managing Security Controls ACCISO Practice Questions (Page 6)

Part of the Information Security Controls and Audit Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts

Questions 26–30

  1. 26application · medium

    A healthcare organization has implemented a new access control system that uses role-based access control (RBAC). Six months later, an audit reveals that several employees have access to patient records they no longer need. Which lifecycle phase was most likely neglected?

    Select an answer first
  2. 27expert · hard

    A financial institution has implemented a new fraud detection system. The system uses machine learning to identify suspicious transactions. After six months, the system is generating a high number of false positives, causing legitimate transactions to be declined and customers to complain. The CISO wants to reduce false positives without increasing the risk of missing actual fraud. What is the best approach?

    Select an answer first
  3. 28application · medium

    A regional bank is rolling out a new customer-facing web portal. The security team must ensure that even if an attacker compromises the web server, they cannot directly access the backend database. The portal will be deployed in phases, starting with a pilot for internal users. Which control design principle should guide the network architecture, and how should the deployment begin?

    Select an answer first
  4. 29foundation · easy

    Which activity is an example of optimizing a security control after an assessment reveals it is not performing effectively?

    Select an answer first
  5. 30application · medium

    A healthcare organization has implemented a new data loss prevention (DLP) system. Six months after deployment, the security team notices that the DLP is generating a high volume of false positives, causing staff to ignore alerts. The CISO wants to improve the effectiveness of the control. What should the security team do first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.