Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 1Objective 4

Risk Management CCISO Practice Questions (Page 8)

Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)

56questions here
12free pages
10concepts

Questions 36–40

  1. 36expert · hard

    A technology company has implemented a risk treatment plan that includes quarterly vulnerability scans and annual penetration tests. After two years, the CISO notices that the number of high-severity vulnerabilities found in scans has not decreased, despite the scans being performed regularly. The CISO suspects that the risk treatment is not effective. Which action should the CISO take to evaluate the effectiveness of the risk treatment?

    Select an answer first
  2. 37application · medium

    A small e-commerce company has identified that its website is vulnerable to a distributed denial-of-service (DDoS) attack. The company's risk appetite is low for availability, but the cost of implementing a full DDoS mitigation service is high. The CISO is considering options. Which risk response is most aligned with the company's risk appetite and budget?

    Select an answer first
  3. 38application · medium

    A manufacturing company is expanding its use of industrial control systems (ICS) by connecting them to the corporate network for remote monitoring. The CISO is leading a risk identification effort. Which approach would best ensure that risks are identified comprehensively?

    Select an answer first
  4. 39application · medium

    A CISO needs to communicate a newly identified critical risk to the CEO. The CEO is not familiar with technical security terminology. What is the most effective way to communicate this risk?

    Select an answer first
  5. 40application · medium

    A large organization has a risk management framework, but employees in different departments do not consistently follow it. The CISO wants to strengthen the risk governance structure. Which action would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.