
EC-CouncilAssociate C|CISO
Domain 2Objective 3
Implementing Control Assurance Frameworks ACCISO Practice Questions (Page 1)
Part of the Information Security Controls and Audit Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
7concepts
Questions 1–5
- 1
An assurance team is planning a control test for a new identity management system. The control requires that all user access requests be approved by the data owner. The team has a limited budget and needs to test the control efficiently. Which testing approach is most appropriate?
Select an answer first - 2
An assurance assessment found that a critical application has a known vulnerability that was not patched within the required timeframe. The CISO needs to report this finding and ensure remediation. What is the most appropriate way to report this finding?
Select an answer first - 3
A company has been using a control assurance framework for several years. The audit results show that the framework is effective, but the CISO wants to improve efficiency by reducing the number of controls that are tested annually. What is the most appropriate approach?
Select an answer first - 4
A control assurance review identified that a critical application has a known vulnerability that could lead to a data breach. The remediation plan requires a vendor patch that will not be available for three months. The CISO must report this to the executive team. What should the report include?
Select an answer first - 5
A global organization operates in regions with conflicting data protection regulations. One region requires strict data residency, another requires rapid cross-border data sharing for fraud detection. The CISO is implementing a control assurance framework and must choose between ISO 27001 and NIST CSF. The organization already has a mature risk management process and needs to demonstrate compliance to multiple regulators. Which approach best balances these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.