
EC-CouncilCertified Chief Information Security Officer
Domain 5Objective 3
Key Performance Indicators (KPI) CCISO Practice Questions (Page 7)
Part of the Strategic Planning, Finance, Procurement, and Vendor Management domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~13–21 in this domain), expect 2–4 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
Questions 31–35
- 31
A healthcare organization's security team has been tracking the percentage of employees who complete mandatory security awareness training. The data is collected from the learning management system (LMS) and reported monthly to the compliance committee. The CISO notices the KPI has plateaued at 92% for three months despite new hires and contractors being added. What is the most appropriate next step?
Select an answer first - 32
A CISO reviews the KPI 'number of security incidents' and notices it has been steadily decreasing. However, the organization's risk level has not changed. What should the CISO do?
Select an answer first - 33
A manufacturing company's CISO wants to develop a KPI to measure the effectiveness of the security operations center (SOC) in containing incidents. The SOC currently tracks the time from detection to containment for each incident. Historical data shows an average of 6 hours, with a best performance of 2 hours. The company's risk appetite requires containing high-severity incidents within 4 hours. What should the CISO set as the initial target for this KPI?
Select an answer first - 34
A regional bank's CISO is building a KPI dashboard for the board. The board wants to see how well the security program is reducing the likelihood of a material data breach. The CISO has access to vulnerability scan data, phishing simulation results, and past incident reports. Which KPI would best align with the board's stated goal?
Select an answer first - 35
A CISO must present the quarterly security KPI report to the executive team. The report includes technical metrics like mean time to detect (MTTD) and mean time to respond (MTTR). The executives are not security experts. What is the best approach to communicate these KPIs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.