
EC-CouncilCertified Chief Information Security Officer
Domain 1Objective 2
Defining an Information Security Governance Program CCISO Practice Questions (Page 4)
Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
8concepts
Questions 16–20
- 16
A mid-sized retail company has just hired its first CISO. The CISO discovers that the IT director approves security budgets, sets security policy, and personally reviews all security incidents. The board has never seen a security report. Which change best aligns with the distinction between governance and management?
Select an answer first - 17
A CISO wants to measure the effectiveness of the security governance program. The board has asked for a single metric that reflects whether the program is reducing the organization's overall risk exposure over time. Which metric is most suitable?
Select an answer first - 18
Which practice best demonstrates alignment of security governance with business strategy?
Select an answer first - 19
How does information security governance align with business strategy?
Select an answer first - 20
A healthcare organization is building its information security governance program from scratch. The CISO wants to ensure that the program includes the essential components to provide direction, enforce accountability, and enable continuous improvement. Which set of components is most complete?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.