
EC-CouncilCertified Chief Information Security Officer
Domain 3Objective 2
Information Security Projects CCISO Practice Questions (Page 5)
Part of the Security Program Management and Operations domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–17 in this domain), expect 3–4 from this objective — we provide 71 practice questions to prepare you well beyond it. (estimate)
71questions here
15free pages
20concepts
Questions 21–25
- 21
Which of the following is an example of a stakeholder in an information security project?
Select an answer first - 22
What is the purpose of change management in an information security project?
Select an answer first - 23
During a vulnerability management project, a critical zero-day vulnerability is discovered in a third-party application that is part of the project's scope. The vendor has not yet released a patch. The project manager must decide how to proceed. What is the BEST risk mitigation approach?
Select an answer first - 24
A security project to implement a new SIEM system has a goal to reduce the mean time to detect (MTTD) security incidents. The project manager needs to define KPIs to measure the project's success. Which KPI is MOST appropriate for this project?
Select an answer first - 25
A manufacturing company's CISO is proposing a project to implement network segmentation to protect intellectual property. The board of directors is concerned about the cost and potential disruption to production. How should the CISO align this project with organizational governance to gain board approval?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.