
EC-CouncilCertified Chief Information Security Officer
Domain 2Objective 2
Security Control Types and Objectives CCISO Practice Questions (Page 5)
Part of the Information Security Controls and Audit Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
4concepts
Questions 21–25
- 21
A company is deciding between investing in a new SIEM system or hiring additional security analysts. The risk assessment shows that the company has a high volume of alerts but a low number of actual incidents. Which decision is most aligned with the risk assessment?
Select an answer first - 22
A retail company is subject to PCI DSS and has a limited budget. A risk assessment shows that the highest risk is cardholder data being stolen from a compromised web server. Which control should the company prioritize?
Select an answer first - 23
A company's security policy states that all employees must wear their ID badges at all times while in the office. This policy is an example of which control type?
Select an answer first - 24
A small business is selecting security controls for its customer database. The risk assessment shows that the data is not highly sensitive, but the business has limited budget. Which control selection approach is most appropriate?
Select an answer first - 25
An online banking platform must ensure that transactions cannot be repudiated by customers. The system currently uses two-factor authentication for login. The security team is considering additional controls. Which control would best enhance non-repudiation for transactions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.