
EC-CouncilCertified Chief Information Security Officer
Domain 2Objective 2
Security Control Types and Objectives CCISO Practice Questions (Page 3)
Part of the Information Security Controls and Audit Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
4concepts
Questions 11–15
- 11
A law firm needs to ensure that only authorized attorneys can access client case files, and that any unauthorized access attempt is recorded. Which combination of security objectives and control types should be implemented?
Select an answer first - 12
A company installs a biometric fingerprint scanner at the entrance to its server room. Which control implementation category does this represent?
Select an answer first - 13
A legal firm must ensure that contracts sent to clients cannot be repudiated by either party. The IT manager proposes using digital signatures and a timestamping service. Which security objectives are being addressed?
Select an answer first - 14
A small business with a limited IT staff needs to protect customer data. They cannot afford a full SIEM solution. Which control selection would be most appropriate given their constraints?
Select an answer first - 15
A data center is implementing multiple layers of security. The security manager is categorizing controls. Which of the following is correctly classified as a technical control?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.