
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 1
Access Controls CCISO Practice Questions (Page 6)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
10concepts
Questions 26–30
- 26
Which of the following is an example of a 'something you have' authentication factor?
Select an answer first - 27
Which of the following is a common access control attack that involves an attacker reusing captured credentials?
Select an answer first - 28
A CISO is designing an access control policy for a financial system. The policy must ensure that no single user can both initiate a wire transfer and approve it. Additionally, users should only have access to the specific functions required for their job. Which combination of principles is being applied?
Select an answer first - 29
What is the primary difference between authentication and authorization?
Select an answer first - 30
A security team is investigating a breach where an attacker used a stolen certificate to authenticate as a legitimate user. The certificate was issued to a user but was stored insecurely. Which IAAA component was most directly compromised?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.