
EC-CouncilCertified Chief Information Security Officer
Domain 3Objective 1
The Role of the CISO CCISO Practice Questions (Page 9)
Part of the Security Program Management and Operations domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~10–17 in this domain), expect 3–4 from this objective — we provide 62 practice questions to prepare you well beyond it. (estimate)
62questions here
13free pages
12concepts
Questions 41–45
- 41
A CISO at a software company is reviewing a new contract with a cloud service provider that will host customer data. The contract includes a clause that limits the provider's liability for data breaches. The CISO is concerned about the organization's legal exposure. What should the CISO do?
Select an answer first - 42
A company's CISO is reviewing a contract with a new cloud provider. The provider's standard terms limit liability for data breaches and do not guarantee data deletion after contract termination. The company handles sensitive personal data. What should the CISO do?
Select an answer first - 43
What is the primary purpose of aligning security initiatives with business goals and objectives?
Select an answer first - 44
A company's CISO is leading the enterprise risk management process. A critical third-party supplier has a known vulnerability that could expose customer data, but replacing the supplier would disrupt operations for months. The CISO must decide how to handle this risk. What is the most appropriate approach?
Select an answer first - 45
Which of the following is an example of a security governance activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.