
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 4
Threat and Vulnerability Management CCISO Practice Questions (Page 1)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
10concepts
Questions 1–5
- 1
What is the role of lessons learned from incidents in vulnerability management?
Select an answer first - 2
What is the first step in the patch management lifecycle?
Select an answer first - 3
A manufacturing company's security team subscribes to a threat intelligence feed that reports a new exploit kit actively targeting a specific version of a widely used industrial control system (ICS) software. The company runs that exact version in several plants. The vendor has not yet released a patch. What should the CISO do first?
Select an answer first - 4
A company is deploying a new application that requires a specific set of ports to be open on the firewall. The security team has a policy that all servers must be hardened according to a baseline. The application vendor recommends disabling the local firewall on the server to ensure compatibility. The CISO must decide how to proceed. What is the best course of action?
Select an answer first - 5
What is the key difference between a vulnerability assessment and a penetration test?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.