
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 1
Access Controls CCISO Practice Questions (Page 5)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
10concepts
Questions 21–25
- 21
What is the purpose of the user access review process in access control administration?
Select an answer first - 22
In the IAAA framework, what is the difference between identification and authentication?
Select an answer first - 23
A company is migrating its on-premises application to the cloud. The application consists of a web server and a database server. The security team wants to ensure that the database is not accessible from the internet, but the web server must be accessible from the internet. Which implementation is the most secure and practical?
Select an answer first - 24
What is the primary purpose of access control in an information security program?
Select an answer first - 25
A security analyst notices multiple failed login attempts for a user account, followed by a successful login at 3:00 AM from an unusual location. The analyst then reviews the user's activity logs and finds that large amounts of data were exported. Which IAAA component is primarily being used to attribute these actions to the user?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.