
EC-CouncilAssociate C|CISO
Domain 2Objective 1
Designing, Deploying, and Managing Security Controls ACCISO Practice Questions (Page 7)
Part of the Information Security Controls and Audit Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 31–35
- 31
A company has implemented a new data loss prevention (DLP) system. After a few months, the security team wants to ensure that the DLP rules are still effective and that they do not block legitimate business processes. What should the team do?
Select an answer first - 32
A company has implemented a security control that requires all employees to use a hardware token for two-factor authentication (2FA). The control is effective, but the company is expanding rapidly and the cost of purchasing and distributing hardware tokens is becoming unsustainable. The CISO wants to maintain the same level of security while reducing costs. What is the best approach?
Select an answer first - 33
A security architect is designing access controls for a new system. The principle of least privilege requires that users be granted:
Select an answer first - 34
A multinational corporation is deploying a new endpoint detection and response (EDR) tool. The security team has limited resources and wants to ensure that the deployment does not disrupt business operations. The company has offices in different time zones. Which deployment approach is most appropriate?
Select an answer first - 35
In the security control management lifecycle, which activity is typically performed during the maintenance phase?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.