
EC-CouncilAssociate C|CISO
Domain 1Objective 4
Risk Management ACCISO Practice Questions (Page 5)
Part of the Governance, Risk, and Compliance domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
10concepts
Questions 21–25
- 21
A financial services firm must comply with a new regulation requiring customer data to be encrypted at rest. The firm currently stores data in a legacy system that does not support encryption. The compliance deadline is in 12 months. What is the most appropriate risk response?
Select an answer first - 22
What is the purpose of risk evaluation and prioritization?
Select an answer first - 23
A CISO needs to report to the board of directors on the organization's top risks. The board is not technical and wants to understand which risks could affect strategic objectives. What is the most effective reporting approach?
Select an answer first - 24
An organization is performing a quantitative risk analysis for a critical application. The asset value is $2 million, the exposure factor is 50%, and the annualized rate of occurrence is 0.2. What is the annualized loss expectancy (ALE)?
Select an answer first - 25
A company is conducting a risk identification workshop for a new cloud migration project. Which techniques are appropriate for identifying risks? Select all that apply.
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.