
EC-CouncilCertified Chief Information Security Officer
Domain 5Objective 5
Return on Investment (ROI) and Cost-Benefit Analysis CCISO Practice Questions (Page 1)
Part of the Strategic Planning, Finance, Procurement, and Vendor Management domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~13–21 in this domain), expect 2–4 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
10concepts
Questions 1–5
- 1
In a cost-benefit analysis for a security project, what is the typical first step?
Select an answer first - 2
A CISO is presenting a business case for a new security awareness training program. The initial ROI calculation assumes a 30% reduction in phishing click rates. During the presentation, the CFO asks how the ROI would change if the reduction were only 15%. What is the most appropriate response?
Select an answer first - 3
A CISO is building a business case for a new vulnerability management program. The CISO has quantified the following benefits: $100,000 per year in avoided breach costs, $50,000 per year in reduced audit findings, and improved security posture. How should the CISO present the 'improved security posture' benefit?
Select an answer first - 4
When evaluating a security project with NPV, what does a positive NPV indicate?
Select an answer first - 5
What does return on investment (ROI) measure in the context of a security investment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.