
EC-CouncilAssociate C|CISO
Domain 1Objective 3
Regulatory and Legal Compliance ACCISO Practice Questions (Page 7)
Part of the Governance, Risk, and Compliance domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
5concepts
Questions 31–35
- 31
A company is found to have violated a data protection regulation by failing to report a breach within the required timeframe. What is the most likely consequence?
Select an answer first - 32
A European e-commerce company is updating its privacy policy to comply with GDPR. The legal team asks the CISO to ensure that the company can demonstrate compliance with the principle of 'data minimization'. Which practice should the CISO implement?
Select an answer first - 33
A company experiences a data breach and fails to notify affected individuals within the timeframe required by state law. What is the most likely consequence?
Select an answer first - 34
A financial services firm is assessing its compliance posture against PCI DSS. The assessment reveals that the company stores full magnetic stripe data after transaction authorization. According to PCI DSS requirements, what is the most appropriate action?
Select an answer first - 35
Which regulatory framework is specifically designed to protect the personal data of individuals within the European Union and imposes obligations on organizations that process such data, regardless of where the organization is located?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.