
EC-CouncilCertified Chief Information Security Officer
Domain 2Objective 1
Designing, Deploying, and Managing Security Controls CCISO Practice Questions (Page 7)
Part of the Information Security Controls and Audit Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
7concepts
Questions 31–35
- 31
A healthcare organization is implementing a new access control system. The project manager wants to minimize disruption to clinical operations while ensuring that the new system is tested and rolled out safely. Which deployment approach best meets these requirements?
Select an answer first - 32
Which method is commonly used to evaluate the effectiveness of a security control?
Select an answer first - 33
A CISO is evaluating the effectiveness of a new data encryption control for data at rest. Which of the following methods would provide meaningful evidence of the control's effectiveness? (Select all that apply.)
Select an answer first - 34
A security team is managing a firewall that has been in place for several years. The team has noticed that the firewall's rule base has grown complex and contains many unused rules. What is the best course of action to maintain the control's effectiveness?
Select an answer first - 35
An organization deploys an intrusion detection system (IDS) that monitors network traffic and generates alerts when suspicious activity is detected. This control is best classified as:
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.