
EC-CouncilCertified Chief Information Security Officer
Domain 1Objective 3
Regulatory and Legal Compliance CCISO Practice Questions (Page 11)
Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
9concepts
Questions 51–55
- 51
A healthcare organization is preparing for a HIPAA compliance audit. The compliance team has identified that several business associates have not signed updated business associate agreements (BAAs). What is the most immediate risk to the organization?
Select an answer first - 52
Which of the following is a non-financial consequence of non-compliance with regulations?
Select an answer first - 53
Which of the following is a primary purpose of the Payment Card Industry Data Security Standard (PCI DSS)?
Select an answer first - 54
What is the primary purpose of a compliance risk assessment?
Select an answer first - 55
An e-commerce company based in the United States sells products to customers in the EU. The company stores customer data in the US and uses a cloud provider with data centers in the EU. Which legal obligation is most relevant to the company's handling of EU customer data?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.