
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 6
Encryption CCISO Practice Questions (Page 1)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
10concepts
Questions 1–5
- 1
A multinational corporation uses a cloud-based key management service (KMS) to store encryption keys for its data-at-rest encryption. The CISO is concerned about the risk of a compromised KMS administrator account. The company has a regulatory requirement to be able to prove that data was encrypted at a specific point in time. Which combination of controls best addresses the CISO's concern while meeting the regulatory requirement?
Select an answer first - 2
A security analyst notices that an attacker is intercepting TLS connections between users and a corporate web application by presenting a fraudulent certificate that the users' browsers accept. Which PKI weakness is most likely being exploited?
Select an answer first - 3
A company wants to secure email communications between its employees and external partners. They decide to use S/MIME. What must be in place for S/MIME to work effectively?
Select an answer first - 4
What is the purpose of key rotation in cryptographic key management?
Select an answer first - 5
A security engineer is designing a system to store user passwords. The current system uses SHA-256 without a salt. The CISO wants to improve password storage security. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.