
EC-CouncilCertified Chief Information Security Officer
Domain 5Objective 6
Vendor Management and Procurement Processes CCISO Practice Questions (Page 6)
Part of the Strategic Planning, Finance, Procurement, and Vendor Management domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~13–21 in this domain), expect 2–4 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
Questions 26–30
- 26
A healthcare organization is negotiating a contract with a cloud EHR vendor. The vendor insists on a limitation of liability clause capped at the total contract value. The CISO is concerned that a data breach could cause damages far exceeding the contract value. The vendor is the only one that meets the organization's technical requirements. What is the best negotiation strategy?
Select an answer first - 27
A company is negotiating a contract with a new cloud provider. The provider's standard contract includes a clause that limits liability to the amount paid in the last 12 months and does not include a data-return clause at the end of the contract. The CISO is concerned about the risk of data loss if the contract is terminated. What is the most important contract term to negotiate?
Select an answer first - 28
A healthcare organization is issuing an RFP for a cloud-based electronic health records system. The RFP team wants to ensure that vendors' security capabilities are comparable. Which approach should the RFP include to achieve this?
Select an answer first - 29
Which contract term is most important to negotiate to ensure the organization can hold the vendor accountable for meeting performance expectations?
Select an answer first - 30
A financial services firm is negotiating a contract with a cloud provider for critical infrastructure. The provider's standard contract includes a clause that limits liability to the value of the contract and does not include a right to audit. The CISO wants to protect the firm's interests. Which contract term should the CISO prioritize?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.