
EC-CouncilCertified Chief Information Security Officer
Domain 1Objective 2
Defining an Information Security Governance Program CCISO Practice Questions (Page 6)
Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
8concepts
Questions 26–30
- 26
A CISO must report to the board on the effectiveness of the security governance program. Which reporting approach is most likely to be understood and valued by the board?
Select an answer first - 27
A logistics company's business strategy emphasizes rapid expansion into new markets. The CISO wants to align the security program with this strategy. Which initiative best supports the business goal?
Select an answer first - 28
A startup has a small security team and wants to build a governance program without over-engineering. They have a business continuity plan and an incident response plan. Which additional component is most essential to complete a basic governance framework?
Select an answer first - 29
A CISO must report to the board on the effectiveness of the security governance program. The board wants to see whether the program is achieving its strategic objectives, such as reducing risk to an acceptable level and improving compliance. Which metric set is most appropriate for this report?
Select an answer first - 30
A CISO is developing a security governance dashboard for the board. The board has asked for a single metric that best reflects the overall health of the governance program. Which metric is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.