Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 1Objective 4

Risk Management CCISO Practice Questions (Page 7)

Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)

56questions here
12free pages
10concepts

Questions 31–35

  1. 31expert · hard

    A CISO must report to the board on a risk that has a low likelihood but a very high potential impact. The board is risk-averse and tends to overreact to high-impact risks. The CISO wants to provide a balanced view. What is the best approach?

    Select an answer first
  2. 32application · medium

    A financial services company is required by regulation to perform an annual risk assessment and report the results to the regulator. The internal audit team also conducts its own risk-based audit plan. The CISO wants to avoid duplication and ensure that both activities are aligned. Which approach should the CISO take?

    Select an answer first
  3. 33application · medium

    A multinational retailer is evaluating the risk of a ransomware attack on its point-of-sale (POS) systems. The CISO's team has estimated that a successful attack would cause $5 million in direct losses and $15 million in reputational damage. Historical data and threat intelligence suggest a 10% probability of occurrence in the next 12 months. The company's risk appetite statement says it will accept risks with an annualized loss expectancy (ALE) below $1 million. Which risk response should the CISO recommend?

    Select an answer first
  4. 34application · medium

    A bank's CISO has completed a risk assessment that identifies a high-severity risk in the mobile banking application. The board of directors is not technically sophisticated and needs to understand the risk in business terms. Which approach should the CISO use to communicate this risk?

    Select an answer first
  5. 35foundation · easy

    Which of the following is an example of a risk report commonly produced for senior management?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.