Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 1Objective 1

Information Security Management Program CCISO Practice Questions (Page 1)

Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)

58questions here
12free pages
10concepts

Questions 1–5

  1. 1foundation · easy

    What is the primary purpose of compliance management within an information security program?

    Select an answer first
  2. 2expert · hard

    A CISO at a manufacturing company is integrating risk management into the security program. The company has a legacy OT (operational technology) environment that controls the production line. A recent risk assessment identified a critical vulnerability in the OT environment that could allow an attacker to stop production. The vendor has released a patch, but applying it requires a production shutdown that would cost an estimated $2 million in lost revenue. The company's risk appetite statement says it will accept risks that cost less than $1 million to mitigate. What is the MOST appropriate decision for the CISO to recommend?

    Select an answer first
  3. 3expert · hard

    A CISO is reviewing the security metrics for the past year. The metrics show that the number of security incidents has decreased by 20%, but the average cost per incident has increased by 35%. The CISO needs to present this data to the board. Which interpretation of this data is MOST accurate?

    Select an answer first
  4. 4application · medium

    A manufacturing company has a security policy that requires all employees to use multi-factor authentication (MFA) for remote access. During a quarterly metrics review, the CISO discovers that the MFA adoption rate is 62% among the sales team, who frequently work from customer sites. The sales director argues that MFA adds friction and slows down client presentations. The CISO needs to improve compliance without damaging the sales team's productivity. Which approach best balances security requirements with business needs?

    Select an answer first
  5. 5application · medium

    A global logistics company has a high rate of phishing incidents. The CISO wants to launch a new security awareness program. The company has a diverse workforce: office-based staff, warehouse workers who do not use email, and long-haul truck drivers who use a mobile app for deliveries. The CISO has a limited budget and must show measurable improvement within six months. What is the MOST effective initial approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.