
EC-CouncilCertified Chief Information Security Officer
Domain 2Objective 4
Understanding the Audit Management Process CCISO Practice Questions (Page 9)
Part of the Information Security Controls and Audit Management domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)
61questions here
13free pages
12concepts
Questions 41–45
- 41
What is the primary purpose of audit follow-up?
Select an answer first - 42
An internal audit team is about to begin an audit of the organization's change management process. The IT operations manager is known to be resistant to audits and may not cooperate fully. What is the most effective communication strategy for the audit team to use with this stakeholder?
Select an answer first - 43
During an audit of a financial services firm, the auditor needs to verify that access to customer records is properly restricted. The auditor has limited time and must gather sufficient evidence. Which combination of evidence-gathering techniques is most effective and efficient?
Select an answer first - 44
Which activity is part of audit quality assurance?
Select an answer first - 45
A newly appointed CISO wants to establish an audit management process for the organization's information security program. The organization has never had formal audits. What is the first step the CISO should take to build an effective audit management process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.