Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilAssociate C|CISO

Domain 2Objective 2

Security Control Types and Objectives ACCISO Practice Questions (Page 5)

Part of the Information Security Controls and Audit Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
4concepts

Questions 21–25

  1. 21application · medium

    A company's security policy states that all sensitive data must be encrypted at rest and in transit. The IT team implements full-disk encryption on laptops and requires HTTPS for all web traffic. Which control types are these?

    Select an answer first
  2. 22application · medium

    A healthcare organization is deploying a new patient-record system. The compliance officer requires that all access to patient records be logged and that any unauthorized access be detected quickly. The system must also ensure that records cannot be altered without detection. Which security control objective is the compliance officer primarily emphasizing?

    Select an answer first
  3. 23application · medium

    A bank is required by regulation to implement segregation of duties. However, due to a small team, one employee must perform two conflicting tasks. The bank implements a mandatory peer-review process for that employee's work. Which type of control is the peer-review process?

    Select an answer first
  4. 24application · easy

    A cloud service provider wants to assure its customers that their data is protected from unauthorized access. The provider implements encryption for data at rest and in transit. Which security control objective is the provider primarily addressing?

    Select an answer first
  5. 25application · medium

    A hospital's IT team discovers that a legacy medical device cannot be patched and has a known critical vulnerability. The device must remain online for patient monitoring. The team decides to isolate the device on a separate network segment and restrict all inbound and outbound traffic except to the monitoring station. Which control type is the team primarily applying?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.