
EC-CouncilCertified Chief Information Security Officer
Domain 5Objective 6
Vendor Management and Procurement Processes CCISO Practice Questions (Page 8)
Part of the Strategic Planning, Finance, Procurement, and Vendor Management domain, which makes up ~21% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~13–21 in this domain), expect 2–4 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
Questions 36–40
- 36
A multinational corporation is evaluating a vendor for a new HR platform. The vendor is based in a country with different data protection laws, and the corporation operates in multiple jurisdictions with varying data residency requirements. The vendor has proposed a single data center location in its home country. The corporation's legal team has flagged that this may violate data residency laws in some jurisdictions. The CISO must balance the need for a standardized platform with regulatory compliance. What is the most appropriate action?
Select an answer first - 37
A regional bank is selecting a new core banking platform vendor. The bank's strategic plan emphasizes rapid digital product launches, but the bank operates in a jurisdiction with strict data-residency rules. The shortlist includes a large global vendor with a mature product and a smaller local vendor with a more flexible development roadmap. The CISO is asked to recommend the primary vendor-selection criterion. Which criterion should the CISO prioritize?
Select an answer first - 38
A software development company is considering a new cloud infrastructure vendor. The vendor is a startup with innovative technology but has limited financial history. The CISO is concerned about the vendor's long-term viability. Which risk assessment action should the CISO take?
Select an answer first - 39
A company is procuring a new customer relationship management (CRM) system. The procurement team has issued the RFP and received proposals from three vendors. The team is now evaluating the proposals. The CISO wants to ensure that security requirements are evaluated consistently. What should the CISO do?
Select an answer first - 40
Which activity is part of the procurement process closure phase?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.