
EC-CouncilCertified Chief Information Security Officer
Domain 2Objective 1
Designing, Deploying, and Managing Security Controls CCISO Practice Questions (Page 3)
Part of the Information Security Controls and Audit Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
7concepts
Questions 11–15
- 11
A multinational corporation is deploying a new identity and access management (IAM) system. The deployment must comply with data residency requirements in the EU and Asia, and the system must integrate with existing on-premises HR systems. The project has a tight deadline. Which deployment approach best balances compliance, integration, and timeline?
Select an answer first - 12
A security architect is designing access controls for a new financial application. The principle of least privilege requires that users be granted:
Select an answer first - 13
When should a security control be decommissioned?
Select an answer first - 14
A security operations team is reviewing the lifecycle of a firewall rule set. They notice that many rules have not been reviewed in over a year, and some rules are no longer needed. What is the best practice for managing these firewall rules?
Select an answer first - 15
A U.S. federal agency must select security controls for its information systems. Which framework is most directly applicable to federal agencies and provides a comprehensive catalog of controls?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.