Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 5Objective 2

Alignment with Business Goals and Risk Tolerance CCISO Practice Questions (Page 6)

Part of the Strategic Planning, Finance, Procurement, and Vendor Management domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~13–21 in this domain), expect 2–4 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
8concepts

Questions 26–30

  1. 26application · medium

    A hospital's board has defined a risk tolerance that prioritizes patient safety over all other factors, including cost. The CISO needs to communicate this to the IT team so that security decisions align. Which communication method is most likely to ensure the IT team understands and applies this tolerance?

    Select an answer first
  2. 27foundation · easy

    What is a key element of effectively communicating risk tolerance?

    Select an answer first
  3. 28application · medium

    A bank's governance structure includes a risk committee that reviews and approves any security control that could impact business operations. The CISO wants to implement a new authentication system that will require users to change passwords more frequently, which may increase help desk calls. What should the CISO do?

    Select an answer first
  4. 29expert · hard

    A government contractor has a low risk appetite for any security incidents because of the sensitive nature of its work. However, the board has set a risk tolerance that allows for a small number of minor incidents per year, as long as no classified data is exposed. The CISO is planning the security budget. Which approach best reflects the board's risk tolerance?

    Select an answer first
  5. 30application · medium

    A regional bank is launching a new mobile banking app that must reach the market within six months to remain competitive. The board has stated that the bank will accept a moderate level of security risk to achieve this timeline, but the CISO is concerned about the app's authentication design. Which action best aligns the security strategy with the board's stated risk tolerance?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.