Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilAssociate C|CISO

Domain 1Objective 4

Risk Management ACCISO Practice Questions (Page 3)

Part of the Governance, Risk, and Compliance domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
10concepts

Questions 11–15

  1. 11application · medium

    A regional bank must align its risk management program with a framework that emphasizes internal control and is widely accepted by external auditors. The bank's board wants a framework that integrates risk with strategy and performance, not just a technical standard. Which framework should the bank adopt?

    Select an answer first
  2. 12application · medium

    A risk manager must present the quarterly risk report to the board of directors. The board is primarily interested in understanding which risks could affect strategic objectives and whether the organization is operating within its risk appetite. Which type of report would best meet the board's needs?

    Select an answer first
  3. 13expert · hard

    A company's risk management program is failing because business units do not report risks in a timely manner. The board wants to improve risk reporting and accountability. Which action would most effectively improve risk governance and culture?

    Select an answer first
  4. 14application · medium

    A global company must comply with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). The risk team is prioritizing compliance risks. Which approach best integrates risk management with compliance obligations?

    Select an answer first
  5. 15expert · hard

    A company faces a risk of a data breach that could result in regulatory fines. The company has three options: (1) implement strong encryption (cost $200,000, reduces likelihood by 80%), (2) purchase cyber insurance (premium $150,000, covers 90% of losses), or (3) do nothing. The risk analysis shows a 15% probability of a $2 million loss. Which option is the most cost-effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.