Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 4Objective 1

Access Controls CCISO Practice Questions (Page 11)

Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)

57questions here
12free pages
10concepts

Questions 51–55

  1. 51application · medium

    An organization uses a file server where each department head can grant read or write access to folders they own. A new employee in the marketing department needs read access to a sales report folder. The sales manager grants the employee read permission. This is an example of which access control model?

    Select an answer first
  2. 52application · medium

    A small business uses a shared network drive for all employees. The owner wants to ensure that only the finance team can access the payroll folder, and that any access to that folder is recorded. What is the most effective way to implement this requirement?

    Select an answer first
  3. 53application · medium

    A company is deploying a new web application that stores sensitive customer data. The security architect wants to ensure that only the application server can access the database, and that database administrators cannot directly query the data from their workstations. Which implementation approach best meets this requirement?

    Select an answer first
  4. 54application · medium

    A small business wants to protect its customer database from unauthorized access. The owner asks the CISO for a simple way to ensure that only employees with a valid username and password can view the data. Which access control component is being implemented?

    Select an answer first
  5. 55application · medium

    An organization is conducting a quarterly access review. The CISO wants to ensure that former employees no longer have active accounts and that current employees have only the permissions needed for their roles. Which process should be performed?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.