Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 1Objective 1

Information Security Management Program CCISO Practice Questions (Page 8)

Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)

58questions here
12free pages
10concepts

Questions 36–40

  1. 36expert · hard

    A CISO is evaluating the effectiveness of the information security program. The organization has a low risk appetite and is subject to strict regulations. Which combination of metrics would provide the most comprehensive view of program effectiveness?

    Select an answer first
  2. 37expert · hard

    A CISO is reviewing the incident response plan after a near-miss incident. During the incident, the IT team detected the breach, but the communication to the executive team was delayed by 6 hours because the incident commander was unsure who had the authority to declare a crisis. The plan is detailed but does not clearly define the decision-making authority for declaring a major incident. The CISO wants to prevent this from happening again. What is the MOST important improvement to make?

    Select an answer first
  3. 38expert · hard

    A healthcare organization is merging with another hospital network. The combined entity will have two different security operations centers (SOCs) with different incident response playbooks, tooling, and escalation paths. The CISO has been asked to unify the incident management capability within 90 days. The organization must maintain compliance with HIPAA breach notification rules throughout the transition. The two SOCs currently have no shared ticketing system and use different severity rating scales. What is the MOST critical first step for the CISO to take?

    Select an answer first
  4. 39application · medium

    After a security incident, a CISO conducts a post-incident review. The review reveals that the incident response team did not have access to the latest threat intelligence. What should the CISO do to improve future response?

    Select an answer first
  5. 40foundation · easy

    In the governance structure of an information security management program, which role typically has ultimate accountability for the program's success?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.