
EC-CouncilAssociate C|CISO
Domain 1Objective 3
Regulatory and Legal Compliance ACCISO Practice Questions (Page 3)
Part of the Governance, Risk, and Compliance domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
5concepts
Questions 11–15
- 11
A company has implemented a compliance monitoring program. The CISO wants to ensure that the program provides timely notification of compliance issues to the appropriate stakeholders. Which practice should be implemented?
Select an answer first - 12
A company is subject to multiple regulations with different reporting cycles. The CISO must design a compliance reporting process that satisfies all stakeholders without overwhelming the compliance team. Which approach is most effective?
Select an answer first - 13
A company is expanding into a new market and must assess its compliance posture against several regulations. The CISO wants to prioritize the assessment based on the potential impact of non-compliance. Which approach should the CISO take?
Select an answer first - 14
A CISO needs to report compliance status to the board but also wants to avoid overwhelming them with technical details. The company is subject to multiple regulations. What is the best approach?
Select an answer first - 15
A company must demonstrate ongoing compliance with SOX for financial reporting. The IT department is responsible for ensuring the integrity of financial systems. Which control is most directly aligned with SOX compliance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.