
EC-CouncilCertified Chief Information Security Officer
Domain 2Objective 1
Designing, Deploying, and Managing Security Controls CCISO Practice Questions (Page 1)
Part of the Information Security Controls and Audit Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
7concepts
Questions 1–5
- 1
A small e-commerce company is designing security controls for its payment processing environment. The compliance team insists on implementing a compensating control because the primary control cannot be deployed due to legacy system limitations. Which example best illustrates a compensating control?
Select an answer first - 2
An organization is migrating its on-premises email system to a cloud-based service. As part of the migration, the CISO must ensure that security controls are integrated with the new system. What is the most important consideration when planning the deployment of security controls for the cloud email service?
Select an answer first - 3
A security team is managing a mix of on-premises and cloud-based security controls. The CISO wants to ensure that all controls are consistently monitored and updated. Which strategy is most effective for managing this heterogeneous control environment?
Select an answer first - 4
A security team is managing a legacy encryption solution that is no longer compliant with current cryptographic standards. The team has identified a replacement, but the migration will require significant downtime. The organization cannot afford extended downtime. Which approach best manages this control lifecycle challenge?
Select an answer first - 5
A mid-sized healthcare organization is required to comply with HIPAA and is adopting a risk-based approach to security. The CISO wants to use a widely recognized framework that provides a structured process for identifying, assessing, and managing cybersecurity risk, while also allowing flexibility to tailor controls to the organization's specific risks. Which framework should the CISO select?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.