Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilAssociate C|CISO

Domain 1Objective 1

Information Security Management Program ACCISO Practice Questions (Page 1)

Part of the Governance, Risk, and Compliance domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
7concepts

Questions 1–5

  1. 1application · medium

    A healthcare organization's ISMP includes a risk register. During a quarterly review, the security team identifies a new vulnerability in the patient portal that could expose protected health information. The exploit is not yet publicly known, but the likelihood of internal misuse is moderate. What should the team do first to integrate this into the ISMP?

    Select an answer first
  2. 2expert · medium

    A financial institution is integrating risk management into its ISMP. The risk assessment identified a critical vulnerability in a legacy system that cannot be patched immediately. The system is essential for daily operations. The CISO must decide how to treat this risk while meeting regulatory requirements and minimizing business disruption. Which approach is most appropriate?

    Select an answer first
  3. 3foundation · easy

    What is the primary difference between a security standard and a security guideline?

    Select an answer first
  4. 4application · medium

    A regional bank is updating its Information Security Management Program (ISMP) to support a new strategic goal of launching a mobile payments app within nine months. The CISO wants the ISMP to directly enable this business objective while still managing risk. Which approach best aligns the ISMP with the bank's strategy?

    Select an answer first
  5. 5application · medium

    After a significant security incident, a manufacturing company is reviewing its Information Security Management Program. The incident revealed gaps in incident response and third-party risk management. The CISO wants to ensure the program improves continuously. Which action is most aligned with a continuous improvement approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.