
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 4
Threat and Vulnerability Management CCISO Practice Questions (Page 4)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
10concepts
Questions 16–20
- 16
A financial services firm recently completed a vulnerability assessment that identified a critical remote code execution flaw in a legacy customer-facing web application. The application cannot be patched immediately because the vendor has not released a fix, and the business cannot take the application offline during normal hours. The CISO must reduce the risk of exploitation while a permanent solution is developed. Which action should the CISO prioritize?
Select an answer first - 17
Which threat category best describes an attacker who uses social engineering to trick an employee into revealing their credentials?
Select an answer first - 18
A retail company has seen an increase in phishing emails targeting its finance department. The emails appear to come from the CEO and request urgent wire transfers. The CISO wants to reduce the likelihood of a successful attack. Which control is most effective for this specific threat?
Select an answer first - 19
A financial firm is deploying a new cloud-based customer relationship management (CRM) system. The security team has created a secure configuration baseline, but the business team wants to enable a feature that requires weakening the baseline (e.g., allowing legacy authentication protocols). The feature is important for a major client. The CISO must decide how to proceed. Which approach best aligns with security governance?
Select an answer first - 20
How does hardening a system reduce its attack surface?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.