
EC-CouncilCertified Chief Information Security Officer
Domain 2Objective 1
Designing, Deploying, and Managing Security Controls CCISO Practice Questions (Page 10)
Part of the Information Security Controls and Audit Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
7concepts
Questions 46–50
- 46
A financial services firm is designing a defense-in-depth strategy for its customer-facing web application. The CISO wants to ensure that a single control failure does not lead to a data breach. Which combination of controls best achieves this objective?
Select an answer first - 47
A manufacturing company is deploying a new network segmentation control to isolate its OT (operational technology) network from the IT network. The deployment must not interrupt production. Which deployment strategy is most appropriate?
Select an answer first - 48
When aligning security controls with regulatory requirements, what is the first step an organization should take?
Select an answer first - 49
A CISO is evaluating the effectiveness of a new endpoint detection and response (EDR) solution. The vendor claims a 99% detection rate, but the organization has seen several false positives that overwhelmed the security team. Which approach provides the most balanced assessment of the EDR's effectiveness?
Select an answer first - 50
A company is implementing a new access control system for its data center. The security team wants to ensure that only authorized personnel can enter the server room, and that access is logged. Which set of controls best meets this requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.