
EC-CouncilAssociate C|CISO
Domain 1Objective 1
Information Security Management Program ACCISO Practice Questions (Page 4)
Part of the Governance, Risk, and Compliance domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
7concepts
Questions 16–20
- 16
A global organization is redesigning its security awareness program. The program must address diverse cultural attitudes toward security, varying levels of technical literacy, and different regulatory requirements in each region. The CISO has limited budget and must demonstrate measurable improvement. Which strategy is most effective?
Select an answer first - 17
A multinational corporation is updating its information security policy framework. The CISO wants to ensure that high-level directives are translated into actionable requirements for different regions and departments. The company has varying regulatory obligations and operational practices across its global offices. Which document hierarchy should the CISO establish to best support consistent yet adaptable implementation?
Select an answer first - 18
A multinational corporation is merging with another company. The CISO must integrate two different Information Security Management Programs. One company has a centralized, compliance-driven program; the other has a decentralized, risk-based program. The merged entity wants to maintain operational efficiency while ensuring consistent security governance. Which approach best balances these competing needs?
Select an answer first - 19
A large enterprise's ISMP includes a metrics program. The CISO must report to the board on the program's effectiveness, but the board is concerned about the cost of security. The CISO wants to demonstrate value while managing costs. Which metric set would best achieve this?
Select an answer first - 20
A retail chain's ISMP is being revised. The company has aggressive growth plans, including entering new international markets. The CISO must ensure the ISMP supports this expansion while maintaining consistent security governance. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.