
EC-CouncilCertified Chief Information Security Officer
Domain 1Objective 3
Regulatory and Legal Compliance CCISO Practice Questions (Page 3)
Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
9concepts
Questions 11–15
- 11
A company suffers a data breach involving personal data of EU residents. The CISO must decide whether to notify the supervisory authority within 72 hours. The breach is low-risk, but the company is unsure if it meets the threshold for notification. What should the CISO do?
Select an answer first - 12
Which of the following is a typical output of a compliance risk assessment?
Select an answer first - 13
What is a potential consequence of non-compliance with data protection regulations such as GDPR?
Select an answer first - 14
A company has implemented a compliance monitoring program, but the board is concerned that the program is not providing actionable insights. The CISO needs to improve the program. What should the CISO do first?
Select an answer first - 15
A company is considering adopting a compliance framework to manage multiple regulatory obligations. The company is a small business with limited resources. Which framework would be most appropriate to start with?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.