
EC-CouncilCertified Chief Information Security Officer
Domain 1Objective 2
Defining an Information Security Governance Program CCISO Practice Questions (Page 11)
Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
8concepts
Questions 51–53
- 51
A newly appointed CISO at a non-profit organization is asked to 'establish security governance.' The organization has never had a formal security program. Which first step best defines the purpose of security governance?
Select an answer first - 52
Which statement best defines information security governance?
Select an answer first - 53
A CISO is designing the governance reporting for the board. The board is concerned about both the level of risk and the performance of the security program. The CISO has limited reporting time and must choose a set of metrics that provides a balanced view. Which set is most balanced?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCISO
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.