
EC-CouncilCertified Chief Information Security Officer
Domain 1Objective 1
Information Security Management Program CCISO Practice Questions (Page 10)
Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
10concepts
Questions 46–50
- 46
Which of the following is a typical phase in the incident response lifecycle?
Select an answer first - 47
A CISO is building the business case for a new security operations center (SOC). The organization currently has no dedicated security monitoring and relies on the IT helpdesk to handle security alerts. The CISO must justify the investment to the CFO. Which approach would be MOST effective in gaining CFO approval?
Select an answer first - 48
A CISO is reviewing the results of a recent risk assessment. The assessment identified a high-risk vulnerability in a legacy system that is critical to operations. The cost to remediate is high, and the system cannot be taken offline easily. What is the most appropriate risk treatment option?
Select an answer first - 49
Which of the following best describes how regulatory requirements should be incorporated into an information security program?
Select an answer first - 50
A regional bank is launching a new mobile payment service that will process cardholder data. The CISO must ensure the security program supports this business initiative while meeting PCI DSS requirements. The bank's risk appetite is moderate, and the board has approved a budget for the initiative. What should the CISO do FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.