Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 2Objective 2

Security Control Types and Objectives CCISO Practice Questions (Page 4)

Part of the Information Security Controls and Audit Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
4concepts

Questions 16–20

  1. 16expert · hard

    A multinational corporation has a policy that all employees must complete annual security awareness training. The training is mandatory, and completion is tracked. However, the company has experienced several phishing incidents where employees clicked on malicious links. The CISO wants to reduce the number of successful phishing attacks. Which control type should be added to complement the existing training?

    Select an answer first
  2. 17application · medium

    A retail company is implementing security controls for its point-of-sale (POS) system. A risk assessment identified that a malware infection could compromise cardholder data, and the company must comply with PCI DSS. Which control selection best addresses the identified risk while meeting the regulatory requirement?

    Select an answer first
  3. 18application · medium

    A manufacturing company wants to prevent unauthorized personnel from entering its server room. The security manager is considering several options. Which option is classified as a physical control?

    Select an answer first
  4. 19foundation · easy

    A security administrator installs motion sensors and video cameras at the entrance of a data center. Which type of security control do these devices primarily represent?

    Select an answer first
  5. 20foundation · easy

    When selecting security controls, an organization first identifies its assets, threats, and vulnerabilities, and then evaluates the likelihood and impact of potential incidents. Which process does this describe?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.