
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 4
Threat and Vulnerability Management CCISO Practice Questions (Page 8)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
10concepts
Questions 36–40
- 36
Which of the following is a common use of a vulnerability scanner?
Select an answer first - 37
A financial services firm's threat intelligence team has been tracking a new banking trojan that is being distributed via malicious Excel macros. The firm's email gateway blocks macros in attachments, but the trojan is also known to spread through USB drives. The firm's endpoint protection has no signature for the trojan yet. What is the most effective immediate action to reduce the risk of infection?
Select an answer first - 38
Which risk assessment framework provides a structured approach to evaluating and treating risks?
Select an answer first - 39
A company has completed a vulnerability assessment that identified several high-risk findings. The CISO wants to validate whether the vulnerabilities are actually exploitable and to test the effectiveness of existing security controls. Which activity should be performed next?
Select an answer first - 40
What is the primary purpose of a vulnerability scanning tool?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.