Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilAssociate C|CISO

Domain 2Objective 2

Security Control Types and Objectives ACCISO Practice Questions (Page 7)

Part of the Information Security Controls and Audit Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
4concepts

Questions 31–35

  1. 31application · medium

    A financial services firm is implementing a new customer portal. The security team has identified that the portal will be exposed to the internet and must protect against credential-stuffing attacks. The compliance team requires that any account lockout be reversible by the help desk without manual database edits. Which combination of control types should the security architect recommend?

    Select an answer first
  2. 32expert · hard

    A security analyst is investigating a potential data breach. The analyst discovers that the intrusion was detected by an alert from the SIEM system, but the attacker had already exfiltrated data. Which control would have been most effective in preventing the exfiltration?

    Select an answer first
  3. 33expert · hard

    A manufacturing company's OT network has legacy PLCs that cannot be patched. The security team must protect them from malware while maintaining production uptime. They are considering: (A) installing host-based antivirus on each PLC, (B) placing the PLCs behind a firewall with strict allowlists, (C) implementing an IDS to monitor traffic, and (D) requiring two-factor authentication for remote access. The team has a limited budget and cannot interrupt production. Which combination of controls best balances risk reduction and operational constraints?

    Select an answer first
  4. 34expert · medium

    A hospital is implementing a new patient portal. The security team must ensure that patient data is not disclosed to unauthorized individuals (confidentiality) and that the portal is available during peak hours (availability). They are considering implementing a load balancer and encryption. Which statement correctly describes the control objectives?

    Select an answer first
  5. 35application · easy

    A manufacturing company is designing a new facility. The security manager wants to prevent unauthorized physical access to the server room. The chosen control is a biometric door lock that only allows entry to authorized personnel. How should this control be classified?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.