
EC-CouncilAssociate C|CISO
Domain 1Objective 1
Information Security Management Program ACCISO Practice Questions (Page 6)
Part of the Governance, Risk, and Compliance domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
7concepts
Questions 26–30
- 26
A retail company's CISO needs to report the effectiveness of the Information Security Management Program to the board. The board wants to see both operational performance and progress toward strategic goals. Which set of metrics would best serve this reporting need?
Select an answer first - 27
What is the primary goal of a security awareness and training program?
Select an answer first - 28
An e-commerce company's ISMP includes a continuous improvement process. A recent audit found that the company's access review process is not consistently followed, leading to excessive user permissions. The CISO wants to address this finding. Which action best supports continuous improvement?
Select an answer first - 29
Which of the following is a trigger for reviewing and improving an ISMP?
Select an answer first - 30
A startup is establishing its first Information Security Management Program. The CEO wants to ensure the program supports business growth and does not become a bureaucratic burden. Which initial approach best aligns with this goal?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.