
EC-CouncilCertified Chief Information Security Officer
Domain 1Objective 2
Defining an Information Security Governance Program CCISO Practice Questions (Page 9)
Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
8concepts
Questions 41–45
- 41
A company has a security policy that is rarely updated and an oversight committee that meets only after a major incident. The CISO wants to improve the governance program. Which change would have the most immediate impact?
Select an answer first - 42
What is a strategic objective of an information security governance program?
Select an answer first - 43
A CISO needs to report to the board on the effectiveness of the security governance program. The board wants to understand whether security investments are reducing risk and whether the program is achieving its strategic objectives. Which reporting approach is most appropriate?
Select an answer first - 44
A government agency is required to adopt a risk-based approach to cybersecurity and must report its security posture to the federal oversight body. The agency wants a framework that provides a common language for cybersecurity risk and is widely used by federal agencies. Which framework is most appropriate?
Select an answer first - 45
What is the primary purpose of information security governance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.