Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 4Objective 4

Threat and Vulnerability Management CCISO Practice Questions (Page 2)

Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)

55questions here
11free pages
10concepts

Questions 6–10

  1. 6foundation · easy

    In a vulnerability assessment, what does the 'quantify' step involve?

    Select an answer first
  2. 7foundation · easy

    How does vulnerability management contribute to incident response?

    Select an answer first
  3. 8foundation · easy

    Which phase of a penetration test involves gathering information about the target without actively engaging with it?

    Select an answer first
  4. 9application · medium

    A company experienced a ransomware incident that originated from an unpatched vulnerability in a public-facing application. The incident response team contained the attack and restored systems from backups. The CISO wants to ensure that the same vulnerability cannot be exploited again. Which action is most important to include in the post-incident improvement plan?

    Select an answer first
  5. 10foundation · easy

    Which of the following is an example of an internal threat to an organization's information assets?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.