
EC-CouncilCertified Chief Information Security Officer
Domain 5Objective 1
Security Strategic Planning CCISO Practice Questions (Page 6)
Part of the Strategic Planning, Finance, Procurement, and Vendor Management domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~13–21 in this domain), expect 2–4 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 26–30
- 26
A university is developing a security strategy with a limited budget. The risk assessment shows that the highest risks are phishing attacks targeting students and faculty, and unpatched vulnerabilities in research systems. The CISO must allocate resources. Which allocation best addresses the identified risks?
Select an answer first - 27
A new CISO at a university is tasked with developing a security strategy. The university values academic freedom and open access to research data, but also must protect student records and research intellectual property. The CISO needs to define the vision and mission of the security strategy. Which statement best reflects a balanced vision?
Select an answer first - 28
A manufacturing company has implemented a new security strategy focused on reducing operational technology (OT) downtime from cyber incidents. The CISO needs to report progress to the board quarterly. Which KPI would most directly measure the success of this strategy?
Select an answer first - 29
A hospital system is developing a security strategy. The risk assessment shows that ransomware attacks on medical devices could cause patient harm and operational disruption. The board has approved a budget that is insufficient to fully mitigate all risks. The CISO must decide how to allocate the budget. Which approach best balances risk reduction and resource constraints?
Select an answer first - 30
A multinational corporation is revising its security strategy. The company operates in regions with varying data protection laws, and a recent geopolitical event has increased the risk of state-sponsored cyber attacks. The CISO must decide how to incorporate these factors. Which approach is most comprehensive?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.