
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 1
Access Controls CCISO Practice Questions (Page 9)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
10concepts
Questions 41–45
- 41
A company is implementing MFA for all users. The CISO is concerned about phishing-resistant authentication. Which MFA method is most resistant to phishing attacks?
Select an answer first - 42
A company has implemented MFA using SMS one-time passcodes. A user reports that they received a text message with a code but did not request it. The user's account is then used to access a sensitive system. Which countermeasure would have most likely prevented this attack?
Select an answer first - 43
A company wants to strengthen remote access authentication for its administrators. Currently, they use only a username and password. The CISO wants to add a second factor that is something the user has. Which of the following would satisfy this requirement?
Select an answer first - 44
A company is implementing a new access control policy. The security team wants to ensure that no single user can both approve a purchase order and create a vendor in the financial system. This is to prevent fraud. Which access control principle is being applied?
Select an answer first - 45
What is a common countermeasure to mitigate the risk of password-based brute-force attacks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.