Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 2Objective 2

Security Control Types and Objectives CCISO Practice Questions (Page 6)

Part of the Information Security Controls and Audit Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
4concepts

Questions 26–30

  1. 26application · easy

    A manufacturing company wants to protect its industrial control systems (ICS) from unauthorized physical access. The site already has perimeter fencing and security guards. The CISO wants to add a control that is primarily physical and preventive. Which option best fits?

    Select an answer first
  2. 27application · easy

    A company is required by a new regulation to implement multi-factor authentication (MFA) for all remote access. The current remote access solution only supports passwords. Which control should the company implement to meet the regulation?

    Select an answer first
  3. 28application · medium

    An e-commerce company wants to ensure that customers can trust that their orders have not been modified after placement. Which control objective and control type best address this?

    Select an answer first
  4. 29expert · hard

    A company has implemented a security information and event management (SIEM) system that collects logs from all servers and applications. The SIEM generates alerts for suspicious activities. However, the security team is overwhelmed by false positives. The CISO wants to improve the effectiveness of the SIEM. Which control type should be enhanced?

    Select an answer first
  5. 30expert · hard

    A hospital is implementing a new patient portal. The CISO must balance patient privacy (confidentiality) with the need for emergency access to records (availability). The risk assessment shows that the biggest threat is unauthorized access by employees. Which control set best balances these objectives?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.