
EC-CouncilCertified Chief Information Security Officer
Domain 2Objective 2
Security Control Types and Objectives CCISO Practice Questions (Page 9)
Part of the Information Security Controls and Audit Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
4concepts
Questions 41–42
- 41
A hospital is required by law to protect patient health information. The security officer must select controls that meet regulatory requirements while also addressing the risks identified in a recent risk assessment. Which approach is most appropriate?
Select an answer first - 42
A multinational company must comply with GDPR for EU customer data and also with a local law requiring data to remain within the country. The CISO must select controls for a new data processing system. The risk assessment shows that the biggest threat is insider misuse. Which control strategy best balances regulatory requirements and the identified risk?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCISO
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.