Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 4Objective 4

Threat and Vulnerability Management CCISO Practice Questions (Page 7)

Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)

55questions here
11free pages
10concepts

Questions 31–35

  1. 31expert · hard

    A company has a mature vulnerability management program, but during a recent incident, the incident response team found that the attacker exploited a vulnerability that was not on the company's vulnerability scan reports. The vulnerability was introduced by a configuration change made by a system administrator. The CISO wants to improve the program to catch such issues. Which change is most effective?

    Select an answer first
  2. 32application · medium

    A manufacturing firm's security team receives threat intelligence that a ransomware group is actively exploiting a remote code execution vulnerability in the VPN appliance used for remote access. The vendor has released an emergency patch, but the patch requires a 15-minute reboot of the VPN, which would disconnect all remote workers. The firm has a 24/7 production schedule. What should the team do first?

    Select an answer first
  3. 33foundation · easy

    Which risk mitigation strategy involves purchasing an insurance policy to cover potential losses from a security breach?

    Select an answer first
  4. 34application · medium

    A healthcare organization wants to verify whether its newly deployed intrusion detection system (IDS) actually detects a known exploit chain that targets its patient portal. The organization has a signed testing agreement with the portal vendor, but the production system contains live patient data. Which approach should the security team take?

    Select an answer first
  5. 35foundation · easy

    When an organization decides to accept a risk, what does that imply?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.