
EC-CouncilAssociate C|CISO
Domain 2Objective 2
Security Control Types and Objectives ACCISO Practice Questions (Page 4)
Part of the Information Security Controls and Audit Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
4concepts
Questions 16–20
- 16
An organization implements a security awareness training program to inform employees about acceptable use policies and the consequences of violations. Which type of control does this represent?
Select an answer first - 17
Which type of security control is primarily designed to stop an incident from occurring in the first place?
Select an answer first - 18
A financial institution is required to comply with a regulation that mandates multi-factor authentication for all remote access. The current VPN solution only supports username and password. The security team has a limited budget and must implement a solution quickly. Which approach is the most appropriate?
Select an answer first - 19
A hospital's electronic health record (EHR) system must be available 24/7. The IT director wants to ensure that in the event of a server failure, the system can be restored quickly. Which control would best address this requirement?
Select an answer first - 20
A risk assessment identifies that an organization's web application is vulnerable to SQL injection attacks. Which control type would be most appropriate to mitigate this specific risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.