
EC-CouncilAssociate C|CISO
Domain 2Objective 3
Implementing Control Assurance Frameworks ACCISO Practice Questions (Page 4)
Part of the Information Security Controls and Audit Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
7concepts
Questions 16–20
- 16
An organization has a mature control assurance framework, but recent audits show that the framework is not keeping pace with new cloud services and DevOps practices. The CISO wants to update the framework to address these changes while maintaining alignment with the existing risk appetite. Which approach best supports continuous improvement?
Select an answer first - 17
What is the purpose of managing remediation actions after identifying control deficiencies?
Select an answer first - 18
When selecting a control assurance framework, which factor is most important to consider first?
Select an answer first - 19
Which input is most valuable for driving continuous improvement of a control assurance framework?
Select an answer first - 20
An assurance team is planning to test the effectiveness of a change management control. The control requires that all production changes have an approved change request and a backout plan. The team has a list of all change requests from the past six months. Which testing procedure provides the strongest evidence that the control is operating effectively?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.