
EC-CouncilCertified Chief Information Security Officer
Domain 5Objective 6
Vendor Management and Procurement Processes CCISO Practice Questions (Page 2)
Part of the Strategic Planning, Finance, Procurement, and Vendor Management domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~13–21 in this domain), expect 2–4 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
Questions 6–10
- 6
A financial services firm is selecting a cloud-based customer relationship management (CRM) vendor. The firm's CISO requires that customer data remain within the country of operation, and the procurement team wants to minimize the number of vendors to manage. The shortlist includes a global CRM provider with a local data center and a regional CRM provider with a strong security track record. Which vendor selection criterion should the CISO emphasize as the primary deciding factor?
Select an answer first - 7
A university is issuing an RFP for a new student information system. The RFP team wants to ensure that vendors provide sufficient detail about their data protection measures. Which section should the RFP include?
Select an answer first - 8
A media company has an SLA with a content delivery network (CDN) vendor that specifies a 99.99% availability target. The vendor has been meeting the target, but the CISO wants to ensure that the vendor's performance is consistently monitored. Which metric should the CISO track?
Select an answer first - 9
A healthcare organization is preparing an RFP for a new electronic health record (EHR) system. The CISO wants to ensure that vendors' security capabilities are thoroughly evaluated. Which action should the CISO take during the RFP development phase?
Select an answer first - 10
A company has decided to terminate its contract with a cloud storage vendor due to repeated security incidents. The contract includes a 90-day transition period. The CISO is responsible for ensuring a smooth exit. Which action should the CISO take first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.