
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 4
Threat and Vulnerability Management CCISO Practice Questions (Page 10)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
10concepts
Questions 46–50
- 46
A retail company's security team is planning a vulnerability assessment of its network. The team needs to identify which systems are exposed to the internet and then prioritize remediation based on the likelihood of exploitation. Which combination of activities best achieves this goal?
Select an answer first - 47
A regional bank has completed a vulnerability assessment and identified a critical SQL injection flaw in a legacy customer-facing web application. The application is scheduled for replacement in 10 months, and the vendor no longer provides patches. The bank's compliance team requires that customer data remain protected in the interim. Which risk treatment approach best balances the bank's constraints?
Select an answer first - 48
A company's risk assessment identifies two significant threats: a disgruntled employee with privileged access who could exfiltrate data, and an external hacker group that has been targeting the company's industry. The company has a limited budget and can only fully address one threat this year. Which factor should most influence the CISO's decision on which threat to address first?
Select an answer first - 49
A regional hospital is evaluating its exposure to ransomware. The IT team has identified that the electronic health record (EHR) system has a known unpatched vulnerability, and the hospital's backup solution has not been tested in over a year. The CISO must decide how to allocate limited security budget. Based on a risk assessment, which combination of actions best reduces the overall risk?
Select an answer first - 50
A university IT team is deploying 200 new Windows workstations for a research lab. The lab's grant agreement requires compliance with a security framework that mandates secure configuration baselines. The team wants to reduce the attack surface while ensuring researchers can still install approved software. Which approach should they take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.