
EC-CouncilAssociate C|CISO
Domain 1Objective 1
Information Security Management Program ACCISO Practice Questions (Page 5)
Part of the Governance, Risk, and Compliance domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
7concepts
Questions 21–25
- 21
A company's ISMP metrics show that the number of security incidents is decreasing, but the average cost per incident is increasing. The board is concerned about the rising costs. The CISO must determine the cause and adjust the program. Which analysis is most likely to identify the root cause?
Select an answer first - 22
Which of the following is an example of a security awareness activity?
Select an answer first - 23
How does an Information Security Management Program (ISMP) best align with organizational strategy?
Select an answer first - 24
Which of the following is a typical component of an Information Security Management Program (ISMP)?
Select an answer first - 25
A hospital's ISMP is being reviewed after an internal audit found that several security controls are not operating effectively. The audit also noted that risk assessments are outdated. The CISO wants to implement a continuous improvement process. Which action is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.