
EC-CouncilCertified Chief Information Security Officer
Domain 2Objective 2
Security Control Types and Objectives CCISO Practice Questions (Page 2)
Part of the Information Security Controls and Audit Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
4concepts
Questions 6–10
- 6
A financial institution must select security controls for its customer data. Which factor should be the primary driver in choosing controls?
Select an answer first - 7
A hospital is implementing a new electronic health record (EHR) system. The security team must ensure that patient data is protected according to HIPAA. The team is considering various controls. Which control is classified as a technical control and directly supports the confidentiality objective?
Select an answer first - 8
An organization implements a security awareness training program that includes disciplinary actions for employees who violate security policies. Which type of control does this represent?
Select an answer first - 9
A company is migrating to a cloud-based infrastructure. The CISO must ensure that the cloud environment meets the same security control objectives as the on-premises environment. Which approach is most appropriate?
Select an answer first - 10
A company's security policy requires that all employees wear ID badges and that visitors sign in at the front desk. Which control types are these?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.