Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 2Objective 1

Designing, Deploying, and Managing Security Controls CCISO Practice Questions (Page 5)

Part of the Information Security Controls and Audit Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
7concepts

Questions 21–25

  1. 21expert · hard

    A security control has been in place for several years, but recent penetration tests have shown that it can be bypassed. The control is still required for compliance. The CISO must decide whether to remediate, replace, or decommission the control. What is the most appropriate decision-making approach?

    Select an answer first
  2. 22application · medium

    A financial services firm is designing a new customer-facing web application that will handle sensitive personal data. The security team has been asked to implement controls that prevent unauthorized access while also ensuring that if a breach occurs, the organization can detect it quickly and restore services. Which combination of control types best meets these requirements?

    Select an answer first
  3. 23expert · hard

    A CISO is reviewing the results of a security control assessment. The assessment found that a critical control is not operating as intended, but the control is required for regulatory compliance. The CISO must decide how to address this finding. Which action is most appropriate?

    Select an answer first
  4. 24application · medium

    A CISO wants to measure the effectiveness of the organization's security awareness training program. Which metric would provide the most meaningful insight into whether the training is changing employee behavior?

    Select an answer first
  5. 25expert · hard

    An organization has implemented a security control that is technically effective but is causing significant user friction, leading to employees finding workarounds. The CISO wants to assess the overall effectiveness of the control. What should the CISO consider?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.