Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 1Objective 4

Risk Management CCISO Practice Questions (Page 1)

Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)

56questions here
12free pages
10concepts

Questions 1–5

  1. 1expert · hard

    A hospital is evaluating two risks: (1) a ransomware attack on its electronic health records (EHR) system, and (2) a failure of its backup power generator during a regional outage. The EHR risk has a high likelihood and high impact, while the generator risk has a low likelihood but very high impact. The hospital's risk appetite is low for patient safety risks but moderate for operational disruptions. The CISO has a limited budget and cannot fully mitigate both risks. Which approach should the CISO take?

    Select an answer first
  2. 2application · medium

    A newly appointed CISO is asked by the board to explain how risk management supports the organization's strategic objectives. Which explanation best describes the role of risk management?

    Select an answer first
  3. 3foundation · easy

    An organization decides to purchase cyber insurance to cover potential losses from a data breach. Which risk response strategy does this represent?

    Select an answer first
  4. 4application · medium

    A software company relies on a third-party cloud provider for its customer database. The provider announces that it will discontinue the current service tier, forcing the company to migrate to a new platform. The CISO assesses that the migration could introduce data integrity issues and service downtime. The company's risk appetite is low for data integrity but moderate for short service interruptions. Which risk response strategy should the CISO choose?

    Select an answer first
  5. 5foundation · easy

    Which risk response strategy involves taking actions to reduce the likelihood or impact of a risk?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.