
EC-CouncilCertified Chief Information Security Officer
Domain 5Objective 4
Financial Planning and Budgeting CCISO Practice Questions (Page 7)
Part of the Strategic Planning, Finance, Procurement, and Vendor Management domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~13–21 in this domain), expect 2–4 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
Questions 31–35
- 31
A global financial services firm is planning its security budget for the next three years. The CISO anticipates new data privacy regulations in several countries, an increase in ransomware attacks, and a planned 20% growth in the company's cloud infrastructure. Which forecasting approach best supports the budget planning?
Select an answer first - 32
A CISO is creating the annual security budget and needs to include a reserve for unexpected security incidents and emergency response. The organization's leadership wants to ensure that the budget is flexible enough to handle unforeseen events. Which budget type should the CISO include?
Select an answer first - 33
A CISO at a multinational corporation is forecasting security funding for the next three years. The company plans to acquire a smaller firm in a region with strict data sovereignty laws. The CISO must also account for a predicted increase in ransomware attacks and the need to upgrade legacy systems. The CFO wants a forecast that is defensible and flexible. Which approach is most appropriate?
Select an answer first - 34
A manufacturing company's CISO is developing the security budget for the upcoming fiscal year. The company's strategic goals include expanding into new international markets and implementing Industry 4.0 technologies. The CISO has gathered input from various department heads and has identified several security initiatives. What should the CISO do to ensure the budget is aligned with organizational goals?
Select an answer first - 35
A regional bank's CISO must justify a new endpoint detection and response (EDR) platform to the CFO. The CFO asks, 'Why should we spend $2 million on this when we already have antivirus?' The CISO has data showing that the current antivirus blocks 60% of malware, while the proposed EDR would block 95% and reduce the average incident response time from 14 days to 2 days. The bank's average cost of a successful malware incident is $1.5 million, and they experience about 10 such incidents per year. Which approach best strengthens the budget justification?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.