Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilAssociate C|CISO

Domain 5Objective 3

Key Performance Indicators (KPI) ACCISO Practice Questions (Page 9)

Part of the Strategic Planning, Finance, Procurement, and Vendor Management domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
8concepts

Questions 41–45

  1. 41application · medium

    A university's CISO wants to measure the percentage of faculty and staff who complete security awareness training. The university uses multiple learning management systems (LMS) across departments, and some training is delivered in person. Which data collection method would provide the most reliable data for this KPI?

    Select an answer first
  2. 42expert · hard

    A CISO is reviewing the quarterly KPI report. The 'percentage of systems with endpoint protection' KPI is at 99%, but the 'number of endpoint compromises' has increased by 20%. The CISO suspects the KPI is not measuring the right thing. What is the most appropriate next step?

    Select an answer first
  3. 43application · medium

    A CISO is preparing a quarterly report for the board. The board wants to understand the overall health of the security program, not just individual metrics. The CISO has data on incident counts, vulnerability remediation rates, and budget variance. Which reporting approach would best serve the board's need?

    Select an answer first
  4. 44expert · hard

    An organization's KPI for 'percentage of endpoints with full disk encryption' has been at 100% for a year. The CISO is reviewing the KPI set and notices that the organization has shifted to a remote-first work model with a mix of corporate and personal devices. What should the CISO do to keep the KPI relevant?

    Select an answer first
  5. 45application · medium

    A CISO wants to track the mean time to detect (MTTD) security incidents. The security team manually logs detection times in a spreadsheet. What is the most critical concern with this data collection method?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.