
EC-CouncilCertified Chief Information Security Officer
Domain 5Objective 4
Financial Planning and Budgeting CCISO Practice Questions (Page 4)
Part of the Strategic Planning, Finance, Procurement, and Vendor Management domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~13–21 in this domain), expect 2–4 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
Questions 16–20
- 16
What is a key advantage of a decentralized funding model for information security?
Select an answer first - 17
A CISO at a mid-sized financial services firm is developing the annual security budget. The firm's strategic plan includes expanding into two new international markets, which will require compliance with local data protection regulations. The CISO must also address a recent increase in phishing attacks targeting employees. The CFO has asked for a budget that clearly demonstrates the value of each security investment. The CISO has identified three initiatives: (1) a security awareness program to reduce phishing risk, (2) a data residency solution for the new markets, and (3) an upgrade to the SIEM platform. The CISO has limited budget and must prioritize. Which initiative should receive the highest priority?
Select an answer first - 18
A government agency's CISO is developing a five-year security budget plan. The agency expects to migrate several systems to the cloud and adopt a zero-trust architecture. The CISO also anticipates changes in federal cybersecurity regulations. What is the most effective way to forecast the security budget over this period?
Select an answer first - 19
A CISO is evaluating funding models for a new security operations center (SOC). The organization has multiple business units with different security needs. The CISO wants to ensure that the SOC provides consistent enterprise-wide monitoring while allowing business units to fund additional monitoring for their specific regulatory requirements. Which funding model is most appropriate?
Select an answer first - 20
A CISO is preparing a budget request for a new security operations center (SOC). The CFO is skeptical about the value of the SOC and asks for a business case. The CISO has data showing that the SOC would reduce the average time to detect and respond to incidents from 72 hours to 4 hours. The company's average cost of a security incident is $500,000, and they experience about 8 incidents per year. The SOC would cost $1.2 million per year to operate. What is the most compelling argument for the SOC?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.