Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 1Objective 4

Risk Management CCISO Practice Questions (Page 9)

Part of the Governance, Risk, and Compliance domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)

56questions here
12free pages
10concepts

Questions 41–45

  1. 41expert · hard

    A financial institution has implemented a risk treatment plan that includes annual penetration tests and continuous security monitoring. After a major security incident, the CISO wants to review the effectiveness of the risk treatment. Which review activity would provide the most useful information?

    Select an answer first
  2. 42application · medium

    A healthcare organization processes patient data and is required by regulation to encrypt data at rest. The current on-premises storage system does not support encryption, and replacing it would cost $2 million. The organization's risk appetite allows accepting low-likelihood, low-impact risks, but the regulatory requirement is mandatory. Which risk response is most appropriate for this risk?

    Select an answer first
  3. 43expert · hard

    A global logistics company is assessing the risk of a prolonged outage of its package tracking system. The system is critical for customer satisfaction and regulatory compliance. The CISO's team has two risk analysis options: a qualitative analysis that rates likelihood as 'high' and impact as 'catastrophic', and a quantitative analysis that estimates a 15% annual probability and $8 million annualized loss. The company's risk tolerance is defined as a maximum acceptable annual loss of $5 million. The CISO must decide which analysis to use for the final risk report to the board. Which decision is most appropriate?

    Select an answer first
  4. 44foundation · easy

    How does integrating risk management with compliance requirements benefit an organization?

    Select an answer first
  5. 45foundation · easy

    Which practice best promotes a risk-aware culture within an organization?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.