
EC-CouncilCertified Chief Information Security Officer
Domain 1Objective 3
Regulatory and Legal Compliance CCISO Practice Questions (Page 8)
Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
9concepts
Questions 36–40
- 36
A global company transfers personal data from its EU headquarters to a subsidiary in a country that does not have an adequacy decision from the EU. The company is considering using Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs). Which factor is most important in deciding between the two?
Select an answer first - 37
A bank is subject to GLBA and must protect customer financial information. Which of the following is a key requirement under the GLBA Safeguards Rule?
Select an answer first - 38
A multinational company headquartered in the EU processes customer data in its US subsidiary. The company is considering a new data processing agreement with a US-based cloud provider. Under the GDPR, what is the most appropriate first step to ensure lawful cross-border data transfer?
Select an answer first - 39
Which legal obligation under the Health Insurance Portability and Accountability Act (HIPAA) applies to covered entities and business associates?
Select an answer first - 40
Which regulatory framework is primarily focused on the protection of personal data of individuals within the European Union?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.