
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 4
Threat and Vulnerability Management CCISO Practice Questions (Page 3)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
10concepts
Questions 11–15
- 11
A mid-sized company's patch management team applies security updates to servers every month. After a recent patch deployment, a critical line-of-business application became unstable, causing a service outage. The CISO wants to reduce the risk of future patch-related outages while still addressing vulnerabilities promptly. Which change to the patch management process is most effective?
Select an answer first - 12
A multinational corporation operates in a country with strict data protection regulations. The company's risk assessment has identified a high likelihood of a specific type of cyberattack, but the cost to fully remediate the vulnerability is very high. The CISO must decide between accepting the risk, transferring it via insurance, or implementing partial controls. The company has a legal obligation to protect customer data. Which decision framework is most appropriate?
Select an answer first - 13
A utility company is conducting a risk assessment for its industrial control system (ICS) network. The assessment identifies a vulnerability in a legacy controller that could allow an attacker to manipulate physical processes. The vendor no longer supports the controller, and replacing it would cost $2 million and take 18 months. The company's safety team estimates that a successful attack could cause $50 million in damages and potential loss of life. The company has a limited budget and must decide on a risk treatment. Which option is the most defensible?
Select an answer first - 14
A company is migrating its on-premises servers to a cloud environment. The CISO wants to ensure that the cloud instances are configured securely from the start. Which practice is most aligned with security configuration management?
Select an answer first - 15
After a ransomware incident, a hospital's security team reviews the timeline and finds that the initial access was gained through a vulnerability that had been identified in a vulnerability scan three months earlier but was not remediated because it was rated medium severity. The team wants to prevent a recurrence. What should the team implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.