Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 5Objective 1

Security Strategic Planning CCISO Practice Questions (Page 10)

Part of the Strategic Planning, Finance, Procurement, and Vendor Management domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~13–21 in this domain), expect 2–4 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
9concepts

Questions 46–50

  1. 46expert · hard

    A hospital system is developing a security strategy. The risk assessment shows that a ransomware attack on the patient portal would have a high impact but low likelihood, while a data breach of the research database would have a moderate impact but high likelihood. The budget is limited. The CISO must decide where to invest. Which decision best reflects a risk-based approach?

    Select an answer first
  2. 47application · medium

    A mid-sized financial services firm is implementing a new security strategy. The CISO has secured budget and executive sponsorship. Which governance structure would best ensure the strategy is implemented effectively and remains aligned with business objectives?

    Select an answer first
  3. 48foundation · easy

    Which of the following is a common method for reviewing and updating a security strategy?

    Select an answer first
  4. 49expert · hard

    A financial institution's security strategy is reviewed annually. This year, the review reveals that the company's KPIs are being met, but a major breach occurred at a competitor using a similar attack vector. The CISO suspects the strategy may have a blind spot. What is the most appropriate action?

    Select an answer first
  5. 50application · medium

    A company's security strategy includes a goal to reduce the number of successful phishing attacks. After a year, the KPI shows that the phishing success rate has dropped from 15% to 10%, but the target was 5%. What should the CISO do next?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.