
EC-CouncilCertified Chief Information Security Officer
Domain 1Objective 4
Risk Management CCISO Practice Questions (Page 3)
Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
10concepts
Questions 11–15
- 11
A retail company is expanding into a new country and will begin processing customer payment data there. The CISO is updating the risk register. Which risk should be identified as a NEW risk introduced by this expansion?
Select an answer first - 12
A CISO is preparing the quarterly risk report for the executive committee. The report should highlight the top risks and the status of risk treatment plans. Which format would be most effective for this audience?
Select an answer first - 13
What is the role of internal audit in relation to risk management?
Select an answer first - 14
What is the primary purpose of risk evaluation and prioritization?
Select an answer first - 15
A healthcare organization has implemented a risk treatment plan to reduce the likelihood of a data breach by encrypting all portable devices and enforcing multi-factor authentication. Six months later, the CISO wants to verify that these controls are still effective and that no new risks have emerged. Which action should the CISO take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.