
EC-CouncilCertified Chief Information Security Officer
Domain 5Objective 3
Key Performance Indicators (KPI) CCISO Practice Questions (Page 1)
Part of the Strategic Planning, Finance, Procurement, and Vendor Management domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~13–21 in this domain), expect 2–4 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
Questions 1–5
- 1
What is the most effective way to communicate KPI results to a non-technical executive audience?
Select an answer first - 2
A CISO wants to track the effectiveness of the security awareness program by measuring the percentage of employees who fall for a simulated phishing campaign. The data is collected from the phishing simulation tool. What is the most important consideration when tracking this KPI over time?
Select an answer first - 3
A technology company's CISO has been using the number of security incidents as a KPI for two years. The KPI has been declining, but the CISO is concerned that the KPI is not providing a complete picture of security performance. The company has also been investing heavily in new security tools. What is the most appropriate action to improve the KPI set?
Select an answer first - 4
Which step is typically the FIRST in the KPI development process?
Select an answer first - 5
A CISO is explaining to a new security analyst why the organization tracks 'percentage of critical assets with an up-to-date asset inventory' as a KPI. Which explanation best describes the role of this KPI?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.