
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 4
Threat and Vulnerability Management CCISO Practice Questions (Page 9)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
10concepts
Questions 41–45
- 41
A government contractor is assessing its threat landscape. The contractor handles classified project data and has recently seen an increase in phishing emails targeting employees. The emails appear to come from a known state-sponsored group. Which threat category best describes this situation, and what is the most appropriate initial mitigation?
Select an answer first - 42
What is the primary purpose of a vulnerability assessment?
Select an answer first - 43
What is the purpose of a security configuration baseline?
Select an answer first - 44
After a security incident, a post-incident review reveals that the organization's vulnerability management program did not include several internet-facing systems that were compromised. The systems were discovered during the incident. The CISO wants to ensure that all internet-facing assets are included in future vulnerability scans. Which action is most effective?
Select an answer first - 45
A mid-sized company has deployed a vulnerability scanner that runs weekly. The scanner reports thousands of findings, many of which are duplicates or false positives. The security team is overwhelmed and missing critical vulnerabilities. What should the team do to improve the effectiveness of its vulnerability management program?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.