
EC-CouncilCertified Chief Information Security Officer
Domain 5Objective 3
Key Performance Indicators (KPI) CCISO Practice Questions (Page 2)
Part of the Strategic Planning, Finance, Procurement, and Vendor Management domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~13–21 in this domain), expect 2–4 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
Questions 6–10
- 6
A CISO wants to measure the effectiveness of the security operations center (SOC). The SOC team is small and often overwhelmed. Which KPI is most appropriate to select?
Select an answer first - 7
A healthcare organization's CISO is selecting KPIs for the security program. The organization has multiple stakeholders: the board wants to see risk reduction, the IT team wants operational metrics, and the compliance team wants regulatory alignment. The CISO must select a set of KPIs that satisfies all stakeholders. Which approach is most effective?
Select an answer first - 8
A CISO is establishing a KPI for the percentage of endpoints with the latest security patches. The organization has no historical data on patch compliance. What is the most appropriate first step in developing this KPI?
Select an answer first - 9
Which statement best defines a Key Performance Indicator (KPI) in the context of organizational performance measurement?
Select an answer first - 10
What is the primary purpose of evaluating the effectiveness of a KPI?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.