Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilAssociate C|CISO

Domain 2Objective 3

Implementing Control Assurance Frameworks ACCISO Practice Questions (Page 2)

Part of the Information Security Controls and Audit Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
7concepts

Questions 6–10

  1. 6application · medium

    A manufacturing company is implementing a control assurance framework based on NIST SP 800-53. The company has a mix of IT and operational technology (OT) systems. The CISO wants to ensure the framework is integrated with existing processes and that assurance activities are prioritized. Which implementation step is most critical to perform early?

    Select an answer first
  2. 7application · medium

    A manufacturing company wants to implement a control assurance framework to improve its security posture. The company operates in a country with strict data protection laws and has a unionized workforce. The CISO must ensure the framework does not conflict with labor agreements. Which step should the CISO take during the scoping phase?

    Select an answer first
  3. 8application · medium

    A company has been using the same control assurance framework for five years. Recent audit results show repeated minor findings in the same control areas, and the business has expanded into a new market with different regulatory requirements. The CISO wants to improve the framework's effectiveness. Which action best supports continuous improvement?

    Select an answer first
  4. 9foundation · easy

    An organization must comply with a regulation that requires a formal, auditable ISMS. Which framework is most appropriate to select?

    Select an answer first
  5. 10application · medium

    A multinational bank must demonstrate to its regulator that IT controls are aligned with business objectives and that control failures are traced to process owners. The bank already has ISO 27001 certification and uses NIST CSF for cyber risk identification. The compliance team wants a framework that provides a governance-level view of IT processes and maps controls to business goals, while also supporting the existing ISO 27001 control set. Which framework should the bank adopt as its primary control assurance framework?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.