
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 6
Encryption CCISO Practice Questions (Page 4)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
10concepts
Questions 16–20
- 16
A security analyst notices that an attacker is intercepting and relaying communications between a user and a legitimate website. The user believes they are communicating directly with the website, but the attacker is capturing and modifying the traffic. Which type of attack is this, and what is the primary mitigation?
Select an answer first - 17
A multinational corporation needs to transfer sensitive legal documents between its headquarters and a branch office. The documents are stored in a cloud file share. The CISO must ensure confidentiality and integrity during transfer. The company already uses a cloud provider that offers TLS for data in transit. What additional measure is most appropriate to provide end-to-end protection beyond TLS?
Select an answer first - 18
A security analyst is investigating a possible brute-force attack on an encrypted file. The analyst knows the file was encrypted with AES-256 and that the password is a 6-character lowercase alphabetic password. Which mitigation would be most effective in preventing this type of attack?
Select an answer first - 19
A company is required to encrypt all sensitive data stored in its database. The database is hosted on a virtual machine in the company's private cloud. The CISO wants to ensure that the encryption keys are not stored on the same server as the data. Which solution should the CISO implement?
Select an answer first - 20
An organization is deploying a new internal application that requires mutual TLS (mTLS) between clients and the server. The organization has an internal CA. The CISO wants to ensure that only company-issued devices can connect. Which configuration should the CISO implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.