
EC-CouncilCertified Chief Information Security Officer
Domain 2Objective 1
Designing, Deploying, and Managing Security Controls CCISO Practice Questions (Page 8)
Part of the Information Security Controls and Audit Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
7concepts
Questions 36–40
- 36
When deploying a new security control, which of the following is a key consideration for integration with existing systems?
Select an answer first - 37
A global organization must comply with both GDPR and the California Consumer Privacy Act (CCPA). The security team is designing a data access control system. Which design consideration is most critical to satisfy both regulations?
Select an answer first - 38
Which security control design principle emphasizes implementing multiple layers of controls so that if one control fails, another is available to prevent or mitigate an attack?
Select an answer first - 39
A security control has been in production for three years. The vendor has announced end-of-life for the product, and the organization is planning to replace it. According to security control lifecycle management, what should the CISO do FIRST?
Select an answer first - 40
How do security controls support the audit process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.