
EC-CouncilCertified Chief Information Security Officer
Domain 1Objective 4
Risk Management CCISO Practice Questions (Page 9)
Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
10concepts
Questions 41–45
- 41
A financial institution has implemented a risk treatment plan that includes annual penetration tests and continuous security monitoring. After a major security incident, the CISO wants to review the effectiveness of the risk treatment. Which review activity would provide the most useful information?
Select an answer first - 42
A healthcare organization processes patient data and is required by regulation to encrypt data at rest. The current on-premises storage system does not support encryption, and replacing it would cost $2 million. The organization's risk appetite allows accepting low-likelihood, low-impact risks, but the regulatory requirement is mandatory. Which risk response is most appropriate for this risk?
Select an answer first - 43
A global logistics company is assessing the risk of a prolonged outage of its package tracking system. The system is critical for customer satisfaction and regulatory compliance. The CISO's team has two risk analysis options: a qualitative analysis that rates likelihood as 'high' and impact as 'catastrophic', and a quantitative analysis that estimates a 15% annual probability and $8 million annualized loss. The company's risk tolerance is defined as a maximum acceptable annual loss of $5 million. The CISO must decide which analysis to use for the final risk report to the board. Which decision is most appropriate?
Select an answer first - 44
How does integrating risk management with compliance requirements benefit an organization?
Select an answer first - 45
Which practice best promotes a risk-aware culture within an organization?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.