Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilAssociate C|CISO

Domain 1Objective 1

Information Security Management Program ACCISO Practice Questions (Page 9)

Part of the Governance, Risk, and Compliance domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
7concepts

Questions 41–45

  1. 41expert · hard

    A financial institution's ISMP has been in place for three years. A recent internal audit found that the risk register is not updated regularly, and several new business units have not been included in the risk assessment process. The CISO must improve the ISMP. Which action is most effective?

    Select an answer first
  2. 42application · medium

    After a security incident, a logistics company's ISMP review reveals that the incident response plan was not followed because the plan was outdated and did not include new cloud-based systems. The CISO wants to apply continuous improvement. What should be the first step?

    Select an answer first
  3. 43expert · hard

    A multinational corporation's ISMP includes a risk management process. The company operates in a region with strict data residency laws, and a new cloud service provider (CSP) offers a cost-effective solution but stores data in a country that does not meet the residency requirement. The CISO must decide how to proceed while integrating risk management into the ISMP. Which approach best balances cost, compliance, and risk?

    Select an answer first
  4. 44expert · medium

    A large enterprise is revising its security policy framework. The CISO wants to ensure that policies are not just documents but are actively used in daily operations. The company has a high turnover rate and a remote workforce. Which approach is most likely to embed policies into the organization's culture?

    Select an answer first
  5. 45application · medium

    A global company's ISMP includes a security awareness program. The program currently offers training only in English, but a significant portion of the workforce speaks Spanish or Mandarin. The CISO wants to improve the program's reach and effectiveness. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.