EC-Council Certified CISO (CCISO) Exam — Questions and Answers
Question 1: When an external auditor identifies a material weakness in internal controls, what must a publicly traded company in the US do under SOX Section 404?
- Replace the internal audit team immediately
- Suspend external audit activities pending board review
- Keep the finding confidential until remediation is complete
- Disclose the material weakness in its annual report and management's assessment (Correct answer)
Correct answer: Disclose the material weakness in its annual report and management's assessment
SOX Section 404 requires management and external auditors to report on internal control effectiveness, including disclosure of any material weaknesses in the annual report.
Question 2: A CISO is building metrics to demonstrate IR program maturity to the board. Which combination of metrics BEST conveys both efficiency and effectiveness of the IR program?
- MTTD, MTTC, MTTR, and incident recurrence rate (Correct answer)
- Number of phishing emails blocked and firewall rule count
- Number of IR team certifications and training hours completed
- Annual IR budget and headcount
Correct answer: MTTD, MTTC, MTTR, and incident recurrence rate
MTTD, MTTC, MTTR, and recurrence rate together measure how quickly threats are found, stopped, recovered from, and whether root causes are addressed, providing a complete maturity picture.
Question 3: Which skill is most critical for effective financial management?
- Communication and stakeholder engagement (Correct answer)
- Individual work preferences
- Technical expertise alone
- Speed of decision-making
Correct answer: Communication and stakeholder engagement
Communication and stakeholder engagement are essential because management success depends on effectively coordinating with and influencing others.
Question 4: Which architectural framework defines security requirements across five concurrent viewpoints: security architecture, security processes, security technology, security assurance, and security governance?
- DoDAF
- SABSA (Sherwood Applied Business Security Architecture) (Correct answer)
- FEAF
- TOGAF Security Extension
Correct answer: SABSA (Sherwood Applied Business Security Architecture)
SABSA is a framework for developing risk-driven enterprise security architectures that links business requirements to security architecture through multiple layered viewpoints.
Question 5: What is the most effective approach to strategic planning in the CCISO field?
- Maintaining the status quo
- Reactive problem-solving
- Following competitors
- Systematic planning and continuous improvement (Correct answer)
Correct answer: Systematic planning and continuous improvement
Systematic planning combined with continuous improvement ensures sustainable success and allows for proactive management of challenges.
Question 6: What is the recommended approach when managing conflicting priorities in CCISO?
- Ignore lower-priority items
- Address them in alphabetical order
- Prioritize based on impact and urgency (Correct answer)
- Delegate all decisions upward
Correct answer: Prioritize based on impact and urgency
Prioritizing based on impact and urgency ensures the most critical issues receive attention first while maintaining progress on other goals.
Question 7: A security team implements a honeypot on the network. What is the PRIMARY purpose of this deception technology?
- Detecting and studying attacker behavior (Correct answer)
- Blocking malicious traffic at the perimeter
- Encrypting sensitive data in transit
- Providing redundancy for critical systems
Correct answer: Detecting and studying attacker behavior
Honeypots are decoy systems designed to attract attackers, allowing security teams to study their tactics and gather threat intelligence.
Question 8: In a risk scenario analysis, the 'exposure factor' (EF) represents:
- The probability that a vulnerability will be exploited
- The cost of implementing a safeguard to protect an asset
- The percentage of asset value lost if a specific threat materializes (Correct answer)
- The frequency with which a threat is expected to occur annually
Correct answer: The percentage of asset value lost if a specific threat materializes
Exposure Factor is the proportion (percentage) of an asset's value that would be lost in a single threat event, used to calculate Single Loss Expectancy.
Question 9: In CCISO practice, what is the primary purpose of strategic planning?
- To reduce workforce
- To satisfy external auditors
- To align resources with goals and anticipate challenges (Correct answer)
- To create paperwork
Correct answer: To align resources with goals and anticipate challenges
Strategic planning aligns organizational resources with goals and helps anticipate challenges before they become critical issues.
Question 10: Under GDPR, what is the maximum time frame for reporting a personal data breach to the supervisory authority after becoming aware of it?
- 72 hours (Correct answer)
- 48 hours
- 24 hours
- 96 hours
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 11: During contract negotiations, a vendor refuses to accept liability for data breaches caused by their negligence. A CISO should PRIMARILY:
- Accept the terms to accelerate procurement
- Seek legal counsel and consider alternative vendors (Correct answer)
- Remove the data security requirements from the contract
- Negotiate a lower service price to offset the risk
Correct answer: Seek legal counsel and consider alternative vendors
Accepting zero vendor liability for negligence-caused breaches transfers all risk to the organization; the CISO should involve legal counsel and evaluate alternatives.
Question 12: What does compliance refer to in risk management?
- Following industry best practices for software development.
- Increasing system speed.
- Adhering to laws, regulations, and standards that govern the security of information and assets. (Correct answer)
- Minimizing operational costs.
Correct answer: Adhering to laws, regulations, and standards that govern the security of information and assets.
In risk management, compliance refers to an organization's adherence to relevant laws, regulations, industry standards, and internal policies concerning information security and asset protection. It ensures that the organization operates legally and ethically, avoiding penalties, legal issues, and reputational damage. Compliance is a critical component of a robust risk management strategy.
Question 13: In strategic planning, which output BEST communicates the security program's current status and forward trajectory to board-level stakeholders?
- Detailed firewall audit logs
- An executive security dashboard with KPIs, KRIs, and roadmap milestones (Correct answer)
- A full network vulnerability report
- Monthly patch management status emails
Correct answer: An executive security dashboard with KPIs, KRIs, and roadmap milestones
Executive dashboards summarize program health through key performance and risk indicators at a level appropriate for board-level decision-making.
Question 14: Just-In-Time (JIT) access provisioning is an IAM strategy that:
- Provides permanent standing privileges to all senior managers
- Pre-provisions all required access rights before an employee starts
- Synchronizes access rights across all systems in real time
- Grants elevated or sensitive access only when needed for a specific task and revokes it immediately afterward (Correct answer)
Correct answer: Grants elevated or sensitive access only when needed for a specific task and revokes it immediately afterward
JIT access eliminates standing privileges by granting temporary, task-specific elevated access on demand, significantly reducing the window of exposure if an account is compromised.
Question 15: Which role is typically responsible for declaring a disaster and formally activating the Business Continuity Plan?
- Any employee who witnesses the incident
- The Crisis Management Team or designated executive authority (Correct answer)
- The Chief Information Security Officer exclusively
- The IT Help Desk Manager
Correct answer: The Crisis Management Team or designated executive authority
Formal disaster declaration authority is granted to a Crisis Management Team or a designated senior executive to ensure consistent, authorized activation of the BCP.
Question 16: Which audit evidence type is generally considered most reliable?
- Evidence provided verbally by management during interviews
- Evidence sourced from third-party documents obtained via the client
- Evidence obtained directly by the auditor through observation and reperformance (Correct answer)
- Evidence from prior year audit working papers
Correct answer: Evidence obtained directly by the auditor through observation and reperformance
Evidence obtained directly by the auditor — through observation, inspection, or reperformance — is considered the most reliable because it is not filtered through the auditee.
Question 17: In the context of IR communications, what is the primary purpose of a crisis communication plan at the executive level?
- To ensure consistent, accurate, and legally vetted messaging to stakeholders, regulators, and the public during an incident (Correct answer)
- To train helpdesk staff on ticket escalation procedures
- To define firewall rule change approval workflows
- To automate SIEM alert triage
Correct answer: To ensure consistent, accurate, and legally vetted messaging to stakeholders, regulators, and the public during an incident
Executive crisis communication plans coordinate messaging across all stakeholder groups to prevent misinformation, manage reputational damage, and ensure legal compliance during incidents.
Question 18: Which forensic principle ensures that evidence collected during an incident investigation is admissible in legal proceedings?
- Deleting logs after analysis to protect privacy
- Conducting analysis on live systems to preserve uptime
- Using the fastest available imaging tool
- Chain of custody documentation (Correct answer)
Correct answer: Chain of custody documentation
Chain of custody documents who handled evidence, when, and how, ensuring its integrity and admissibility in court.
Question 19: A CISO is tasked with aligning the security roadmap to a 3-year business transformation. Which planning horizon best describes this effort?
- Operational planning
- Tactical planning
- Strategic planning (Correct answer)
- Contingency planning
Correct answer: Strategic planning
Strategic planning addresses long-term goals (typically 3–5 years) and aligns security initiatives with overall business direction.
Question 20: Which architectural design decision BEST protects against cryptographic algorithm obsolescence (cryptographic agility)?
- Using proprietary encryption algorithms developed in-house
- Hardcoding the strongest currently available algorithm into all applications
- Avoiding encryption for internal communications to reduce complexity
- Designing systems to abstract cryptographic functions so algorithms can be swapped without major code changes (Correct answer)
Correct answer: Designing systems to abstract cryptographic functions so algorithms can be swapped without major code changes
Cryptographic agility means designing systems so cryptographic primitives are abstracted and configurable, allowing organizations to update algorithms as standards evolve or vulnerabilities are discovered without application redesign.
Question 21: A CISO is negotiating a cloud security contract and encounters a limitation of liability clause capping vendor damages at one month's fees. What financial risk management strategy should the CISO recommend?
- Supplement with cyber insurance to cover losses exceeding the contractual cap (Correct answer)
- Renegotiate to a cap of six months' fees as an industry standard
- Require an escrow account equal to projected maximum losses
- Accept the clause as standard industry practice
Correct answer: Supplement with cyber insurance to cover losses exceeding the contractual cap
When contractual liability caps fall short of potential loss exposure, cyber insurance fills the financial gap between what the vendor will pay and actual breach costs.
Question 22: Which US executive order significantly shaped federal cybersecurity requirements for critical infrastructure and established information-sharing between the private sector and government?
- EO 13800
- EO 13636
- EO 14028 (Correct answer)
- EO 13556
Correct answer: EO 14028
Executive Order 14028 (2021) on Improving the Nation's Cybersecurity modernized federal security standards, mandated zero trust architecture, and enhanced software supply chain security.
Question 23: A CISO must present the security program's value to the board. Which metric BEST demonstrates the effectiveness of security controls from a business risk perspective?
- Number of firewall rules updated per quarter
- Percentage of employees who completed security awareness training
- Reduction in risk exposure measured in dollar value (Correct answer)
- Total number of security incidents detected
Correct answer: Reduction in risk exposure measured in dollar value
Boards understand financial risk; expressing risk reduction in dollar value directly connects security investments to business outcomes they can evaluate.
Question 24: In the context of supply chain resilience within BCP, which practice best mitigates single-supplier risk?
- Maintaining a list of qualified alternate suppliers for critical components (Correct answer)
- Transferring supplier risk entirely to cyber insurance
- Increasing on-site inventory to six months' supply
- Negotiating lower prices with the existing supplier
Correct answer: Maintaining a list of qualified alternate suppliers for critical components
Pre-qualifying alternate suppliers ensures the organization can quickly pivot to another source if the primary supplier is disrupted, reducing single-point-of-failure risk.
Question 25: A CISO identifies that a critical vendor managing customer PII has no cyber insurance. Under a shared risk model, what financial control should the CISO recommend?
- Purchase additional cyber insurance to cover the vendor's risk
- Classify the vendor as a low-risk third party
- Terminate the vendor contract immediately
- Require the vendor to obtain adequate cyber liability insurance as a contractual obligation (Correct answer)
Correct answer: Require the vendor to obtain adequate cyber liability insurance as a contractual obligation
Requiring vendors to maintain cyber liability insurance transfers financial risk back to the vendor and is a standard third-party risk management contractual control.
Question 26: The principle of least privilege in IAM requires that users be granted:
- Administrator rights to perform their duties efficiently
- Read access to all company data for transparency
- Full access during business hours and no access after hours
- Access only to the resources and data necessary to perform their assigned job functions (Correct answer)
Correct answer: Access only to the resources and data necessary to perform their assigned job functions
Least privilege minimizes the attack surface by limiting user permissions to only what is required for their specific role, reducing risk from insider threats and compromised accounts.
Question 27: During a closing meeting, the auditee disputes a finding. What is the auditor's best response?
- Document the dispute and include management's response in the final report (Correct answer)
- Defer the finding to the next audit cycle
- Remove the finding to maintain the relationship
- Escalate immediately to legal counsel
Correct answer: Document the dispute and include management's response in the final report
Documenting the dispute and including management's rebuttal preserves objectivity and provides a complete record in the final report.
Question 28: Which BCP component ensures employees know their roles and responsibilities during a disruption?
- Awareness and Training Program (Correct answer)
- Crisis Communication Plan
- Business Impact Analysis
- Occupant Emergency Plan (OEP)
Correct answer: Awareness and Training Program
Awareness and training programs ensure all personnel understand their BCP roles, enabling coordinated and effective response during an actual disruption.
Question 29: A CISO needs to secure a SCADA/ICS environment. Which architectural principle is MOST critical when integrating ICS with corporate IT networks?
- Network segmentation with strict access controls and unidirectional security gateways where possible (Correct answer)
- Implementing single sign-on across both environments
- Using the same patch management cycle for both environments
- Deploying cloud-based monitoring for ICS devices
Correct answer: Network segmentation with strict access controls and unidirectional security gateways where possible
ICS/SCADA environments require strict network segmentation from corporate IT networks, often using unidirectional data diodes, because these systems prioritize availability over confidentiality and cannot tolerate standard IT security disruptions.
Question 30: A security analyst discovers that an attacker modified audit logs to hide intrusion evidence. Which security principle was violated?
- Availability
- Non-repudiation
- Confidentiality
- Integrity (Correct answer)
Correct answer: Integrity
Integrity ensures data is accurate and unaltered; tampering with audit logs directly violates this principle.
Question 31: Which framework is most commonly used to cascade high-level security strategy into measurable departmental objectives?
- NIST RMF
- COBIT 2019
- ISO 27001 Annex A
- Balanced Scorecard (Correct answer)
Correct answer: Balanced Scorecard
The Balanced Scorecard translates strategic vision into four perspectives—financial, customer, internal process, and learning—with linked KPIs.
Question 32: In network security architecture, what does 'east-west traffic' refer to, and why is it a growing concern?
- Lateral traffic between servers within the same data center or cloud environment (Correct answer)
- Traffic between US and European data centers
- Encrypted traffic bypassing DLP controls
- Traffic from mobile endpoints to corporate servers
Correct answer: Lateral traffic between servers within the same data center or cloud environment
East-west traffic refers to lateral communication between workloads within the same environment; it is a concern because attackers who breach the perimeter can move laterally without being detected by perimeter controls.
Question 33: A CISO is designing a cloud security architecture. Which framework provides a comprehensive set of security controls specifically tailored for cloud environments?
- ISO 27001 Annex A
- CIS Controls v8
- CSA Cloud Controls Matrix (CCM) (Correct answer)
- NIST SP 800-53
Correct answer: CSA Cloud Controls Matrix (CCM)
The CSA Cloud Controls Matrix (CCM) is specifically designed to provide security control requirements and guidance for cloud computing environments.
Question 34: What is the architectural difference between an Intrusion Detection System (IDS) and an Intrusion Prevention System (IPS) in terms of network placement?
- IDS is typically placed out-of-band (passive monitoring) while IPS is placed inline (active blocking) (Correct answer)
- IDS operates at Layer 7 while IPS operates at Layer 3
- IDS is always cloud-based while IPS is on-premises
- IDS requires more bandwidth than IPS
Correct answer: IDS is typically placed out-of-band (passive monitoring) while IPS is placed inline (active blocking)
IDS is deployed out-of-band to passively monitor and alert on suspicious traffic, while IPS is deployed inline and can actively block malicious traffic in real time.
Question 35: An organization uses a hot site for disaster recovery. What distinguishes a hot site from a warm site?
- A hot site requires 24–72 hours to become operational
- A hot site has fully operational systems with real-time data replication (Correct answer)
- A hot site is geographically closer to the primary site
- A hot site only stores backup media
Correct answer: A hot site has fully operational systems with real-time data replication
A hot site is a fully equipped and operational duplicate facility with real-time or near-real-time data replication, enabling near-immediate failover.
Question 36: When a CCISO professional faces pressure to compromise professional standards, the BEST response is to:
- Ignore the pressure and continue without reporting
- Comply to maintain workplace relationships
- Immediately resign from the position
- Document the pressure and uphold professional standards (Correct answer)
Correct answer: Document the pressure and uphold professional standards
Professionals should document any pressure to compromise standards and continue upholding their professional obligations. Documentation creates a record of the situation while maintaining ethical integrity.
Question 37: Under COBIT 2019, which governance objective directly supports the audit management function by ensuring IT-related risks are identified and managed?
- BAI09 — Managed Assets
- DSS05 — Managed Security Services
- MEA01 — Managed Performance and Conformance Monitoring
- APO12 — Managed Risk (Correct answer)
Correct answer: APO12 — Managed Risk
APO12 (Managed Risk) in COBIT 2019 governs the identification, assessment, and response to IT-related risks, directly supporting audit management activities.
Question 38: When designing a security architecture for a containerized environment, which control is MOST effective at preventing container escape attacks?
- Encrypting container images at rest
- Scanning container images for known CVEs before deployment
- Using private container registries
- Enforcing kernel namespace isolation and running containers with non-root user contexts and read-only file systems (Correct answer)
Correct answer: Enforcing kernel namespace isolation and running containers with non-root user contexts and read-only file systems
Container escape prevention relies on kernel namespace isolation, dropping unnecessary capabilities, running as non-root, and using read-only file systems to limit what an attacker can do even if they compromise a container.
Question 39: During incident containment, the IR team isolates an infected endpoint by removing it from the network. This action is BEST classified as which type of containment?
- Eradication phase activity
- Long-term containment with remediation
- Short-term containment to limit immediate spread (Correct answer)
- Recovery phase restoration
Correct answer: Short-term containment to limit immediate spread
Network isolation of an infected endpoint is a short-term containment measure that limits the immediate spread of an incident while investigation and eradication planning proceed.
Question 40: A CISO is responsible for ensuring that incident response capabilities scale appropriately as the organization grows. Which approach BEST supports scalable IR capability over time?
- Hiring a fixed-size IR team and maintaining static playbooks indefinitely
- Implementing a tiered response model with defined escalation paths, regularly updated playbooks, and integration of automation for high-volume, low-complexity incidents (Correct answer)
- Outsourcing all IR activities permanently with no internal capability
- Relying solely on law enforcement for all incident response activities
Correct answer: Implementing a tiered response model with defined escalation paths, regularly updated playbooks, and integration of automation for high-volume, low-complexity incidents
A tiered model with escalation paths, living playbooks, and automation handles increasing incident volume efficiently while preserving human judgment for complex events.
Question 41: A CISO's strategic plan includes a zero-trust network architecture initiative. Which business driver MOST likely justified this investment?
- Budget surplus at the end of the fiscal year
- Regulatory mandate requiring zero-trust specifically
- Increasing remote work and cloud adoption that eroded traditional perimeter controls (Correct answer)
- Desire to reduce the number of security vendors
Correct answer: Increasing remote work and cloud adoption that eroded traditional perimeter controls
Zero-trust architectures are primarily driven by the dissolution of network perimeters due to remote work, cloud services, and mobile devices.
Question 42: A publicly traded company's CISO must ensure that material cybersecurity incidents are disclosed per SEC rules. What is the primary financial risk of late or inaccurate disclosure?
- Mandatory security audit by the Federal Reserve
- Loss of PCI DSS certification
- Increased cyber insurance deductibles
- SEC enforcement actions, fines, and shareholder litigation (Correct answer)
Correct answer: SEC enforcement actions, fines, and shareholder litigation
Under SEC cybersecurity disclosure rules, late or inaccurate material incident reporting exposes the company to SEC enforcement, civil penalties, and securities fraud litigation.
Question 43: A gap analysis in security strategic planning compares which two states?
- Current security posture vs. desired future-state security posture (Correct answer)
- Budgeted spend vs. actual spend
- Compliance status vs. regulatory requirements
- Attacker capabilities vs. defender capabilities
Correct answer: Current security posture vs. desired future-state security posture
A gap analysis identifies the delta between where the organization is today and where it needs to be to meet strategic security objectives.
Question 44: Under ISO/IEC 27005, the risk evaluation step is performed to:
- Implement controls selected from ISO/IEC 27002
- Identify all assets within scope of the ISMS
- Document residual risk after controls are applied
- Compare risk analysis results against risk criteria to prioritize treatment (Correct answer)
Correct answer: Compare risk analysis results against risk criteria to prioritize treatment
Risk evaluation compares the estimated risk levels against pre-established risk criteria to determine which risks require treatment and their priority.
Question 45: In CCISO practice, what is the primary purpose of strategic planning?
- To reduce workforce
- To satisfy external auditors
- To create paperwork
- To align resources with goals and anticipate challenges (Correct answer)
Correct answer: To align resources with goals and anticipate challenges
Strategic planning aligns organizational resources with goals and helps anticipate challenges before they become critical issues.
Question 46: In the context of enterprise risk management, what does 'risk appetite' define?
- The probability threshold above which all risks must be mitigated
- The residual risk remaining after all controls are applied
- The amount of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The maximum loss an organization can absorb before becoming insolvent
Correct answer: The amount of risk an organization is willing to accept in pursuit of its objectives
Risk appetite represents the board-level decision about how much risk the organization is willing to tolerate while pursuing strategic goals.
Question 47: A CISO is developing a vendor exit strategy. Which element is MOST critical to include to protect the organization's sensitive information?
- Vendor's future client list
- Transfer of vendor's source code to competitors
- Vendor employee retention bonuses
- Data destruction or certified return procedures with proof of completion (Correct answer)
Correct answer: Data destruction or certified return procedures with proof of completion
A vendor exit strategy must include certified data destruction or return processes with documented proof to ensure sensitive information is not retained by the departing vendor.
Question 48: In the context of CCISO strategic planning, 'strategic risk' is BEST defined as:
- Risks arising from day-to-day IT operations
- Risks documented in the vulnerability scanner
- Regulatory fines for non-compliance
- Risks that could prevent the organization from achieving its long-term business objectives (Correct answer)
Correct answer: Risks that could prevent the organization from achieving its long-term business objectives
Strategic risk refers to high-level uncertainties that threaten the organization's ability to execute its long-term strategy.
Question 49: What is the MOST effective way for new CCISO professionals to build competency in their field?
- Studying certification materials exclusively
- Learning entirely through trial and error
- Focusing solely on the most advanced topics
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building professional competency requires a multi-faceted approach: formal education provides foundational knowledge, mentored practice develops applied skills under guidance, and ongoing professional development ensures continuous growth and currency in the field.
Question 50: A CISO discovers that a cloud provider is subcontracting data processing to a fourth-party vendor without notification. This PRIMARILY violates which principle?
- Data minimization
- Due diligence in vendor chain management (Correct answer)
- Least privilege
- Defense in depth
Correct answer: Due diligence in vendor chain management
Undisclosed subcontracting represents a failure of supply chain due diligence, which requires visibility and control over all parties handling organizational data.
Question 51: Which of the following BEST describes the purpose of a Statement of Applicability (SoA) in ISO 27001?
- Defines the scope of the ISMS boundary
- Lists applicable controls and justifies inclusions and exclusions (Correct answer)
- Outlines the business continuity plan
- Documents the organization's risk appetite
Correct answer: Lists applicable controls and justifies inclusions and exclusions
The SoA documents which Annex A controls are applicable, their implementation status, and the justification for including or excluding each control.
Question 52: A CISO learns that a key vendor has been acquired by a competitor. What is the FIRST action the CISO should take from a vendor risk management perspective?
- Immediately terminate the vendor contract
- Ignore the acquisition until the contract renewal date
- Re-assess the vendor's risk profile and review contract change-of-control provisions (Correct answer)
- Transfer all vendor-held data to internal systems immediately
Correct answer: Re-assess the vendor's risk profile and review contract change-of-control provisions
A change-of-control event warrants an immediate re-assessment of the vendor's risk posture and a review of any contractual provisions triggered by ownership changes.
Question 53: When conducting a SWOT analysis for information security strategy, which quadrant specifically examines internal deficiencies that could hinder security objectives?
- Threats
- Strengths
- Opportunities
- Weaknesses (Correct answer)
Correct answer: Weaknesses
Weaknesses represent internal deficiencies such as skill gaps, legacy systems, or budget constraints that can undermine security goals.
Question 54: During strategic planning, a CISO identifies that a proposed cloud migration increases residual risk beyond the board's appetite. The BEST response is to:
- Escalate findings and propose risk treatment options to leadership (Correct answer)
- Transfer all risk to the cloud provider
- Halt the migration indefinitely
- Accept the risk without disclosure
Correct answer: Escalate findings and propose risk treatment options to leadership
The CISO should surface findings to decision-makers and present treatment options so leadership can make informed risk-acceptance decisions.
Question 55: A third-party vendor will process sensitive customer data. Which contractual mechanism BEST ensures compliance with data protection requirements?
- Non-Disclosure Agreement (NDA)
- Master Service Agreement (MSA)
- Service Level Agreement (SLA)
- Data Processing Agreement (DPA) (Correct answer)
Correct answer: Data Processing Agreement (DPA)
A Data Processing Agreement legally defines how a third party must handle personal data and is required under regulations like GDPR.
Question 56: Why is communication essential during incident response?
- To monitor financial losses.
- To provide updates to the press.
- To increase employee engagement.
- To ensure stakeholders are informed and coordinated during response efforts. (Correct answer)
Correct answer: To ensure stakeholders are informed and coordinated during response efforts.
Communication is essential during incident response to ensure that all relevant stakeholders are informed, coordinated, and aligned throughout the response efforts. This includes internal teams, management, legal counsel, and potentially external parties like customers or regulators. Clear and timely communication helps manage expectations, maintain trust, and facilitate a smooth and effective resolution.
Question 57: A CISO wants to reduce audit fatigue caused by multiple simultaneous audits from different regulators. Which strategy is most effective?
- Implement a coordinated audit management program that consolidates evidence collection and aligns audit schedules (Correct answer)
- Automate all control tests to eliminate manual evidence gathering
- Refuse redundant audits citing resource constraints
- Delegate all regulatory responses to legal counsel
Correct answer: Implement a coordinated audit management program that consolidates evidence collection and aligns audit schedules
A coordinated audit management program consolidates evidence artifacts and aligns scheduling to reduce redundant requests and minimize disruption to operations.
Question 58: What is the PRIMARY purpose of obtaining CCISO certification in EC-Council Certified CISO?
- To demonstrate verified competency and adherence to professional standards (Correct answer)
- To bypass educational requirements
- To guarantee employment in the field
- To satisfy a personal achievement goal
Correct answer: To demonstrate verified competency and adherence to professional standards
Professional certification demonstrates that an individual has met established competency standards through verified assessment. It provides assurance to employers, clients, and the public that the certified professional possesses the knowledge and skills required for competent practice.
Question 59: Which of the following BEST describes the concept of 'security by design' in program management?
- Designing a security awareness curriculum
- Incorporating security requirements and controls into systems from their initial design phase (Correct answer)
- Installing security cameras throughout corporate facilities
- Designing secure physical office spaces for the security team
Correct answer: Incorporating security requirements and controls into systems from their initial design phase
Security by design means embedding security considerations from the earliest stages of system design rather than adding them after development.
Question 60: The concept of 'privacy by design' requires organizations to embed privacy protections into systems from the outset. Which GDPR article explicitly codifies this requirement?
- Article 17
- Article 25 (Correct answer)
- Article 5
- Article 32
Correct answer: Article 25
GDPR Article 25 mandates Data Protection by Design and by Default, requiring controllers to integrate data protection into processing activities from the design stage.
Question 61: In audit terminology, what does 'materiality' determine?
- The number of sample items required for statistical validity
- The threshold above which misstatements or control gaps are significant enough to report (Correct answer)
- The classification level of audit working papers
- The legal admissibility of audit evidence
Correct answer: The threshold above which misstatements or control gaps are significant enough to report
Materiality is the threshold at which a misstatement or deficiency is significant enough to affect decisions or require reporting.
Question 62: Why is risk assessment critical in information security management?
- To improve organizational marketing strategies.
- To track employee activities.
- To increase system efficiency.
- To identify and mitigate risks to sensitive information. (Correct answer)
Correct answer: To identify and mitigate risks to sensitive information.
Risk assessment is a foundational step in information security because it systematically identifies potential threats and vulnerabilities that could harm sensitive information. By understanding these risks, organizations can prioritize which ones to address first and implement appropriate controls. This proactive approach helps in allocating resources effectively to mitigate the most significant dangers.
Question 63: A CISO is drafting a vendor contract and wants to include language addressing regulatory compliance failures. Which contract clause specifically allocates responsibility and financial exposure for compliance violations between parties?
- Force majeure clause
- Service level agreement (SLA)
- Indemnification clause (Correct answer)
- Limitation of liability clause
Correct answer: Indemnification clause
An indemnification clause allocates financial responsibility by requiring one party to compensate the other for losses arising from regulatory violations, breaches, or negligence.
Question 64: When integrating cybersecurity into enterprise risk management (ERM), the CISO's role is to:
- Translate cyber risks into business-impact terms understood by risk and finance executives (Correct answer)
- Manage only technical risks within the IT department
- Replace the Chief Risk Officer's responsibilities
- Eliminate all residual cyber risk
Correct answer: Translate cyber risks into business-impact terms understood by risk and finance executives
The CISO bridges the gap between technical cyber risk and business risk language so that cyber risks are properly reflected in the ERM framework.
Question 65: Under a risk-based audit approach, which area would an internal auditor prioritize FIRST?
- Business units with the highest revenue
- Systems last audited over three years ago regardless of risk
- Processes with the highest inherent risk and weakest controls (Correct answer)
- Departments with the largest headcount
Correct answer: Processes with the highest inherent risk and weakest controls
Risk-based auditing directs attention to areas where high inherent risk combines with inadequate controls, representing the greatest exposure.
Question 66: A CISO is building a Total Cost of Ownership (TCO) model for a new SIEM platform. Which component is most commonly underestimated in TCO calculations?
- Integration, training, and ongoing maintenance costs (Correct answer)
- Initial implementation fees
- Hardware procurement costs
- Licensing fees
Correct answer: Integration, training, and ongoing maintenance costs
TCO models often underestimate indirect costs like staff training, system integration labor, and ongoing maintenance, which frequently exceed initial procurement costs.
Question 67: A CISO is selecting between two vendors: one holds ISO 27001 certification and the other provides a SOC 2 Type II report. Which statement BEST describes the difference?
- SOC 2 is a certification; ISO 27001 is an audit report
- ISO 27001 certifies an ISMS against a standard; SOC 2 Type II reports on operational effectiveness of controls over a period (Correct answer)
- Both certifications are identical in scope and value
- ISO 27001 is US-specific; SOC 2 is international
Correct answer: ISO 27001 certifies an ISMS against a standard; SOC 2 Type II reports on operational effectiveness of controls over a period
ISO 27001 is a management system certification, while SOC 2 Type II is an attestation report covering the operational effectiveness of controls over a defined review period.
Question 68: Which governance structure BEST ensures security strategic decisions receive appropriate executive-level oversight?
- An internal audit department review
- A weekly technical security team standup
- A security steering committee with C-suite and board representation (Correct answer)
- A departmental IT risk committee
Correct answer: A security steering committee with C-suite and board representation
A security steering committee with executive and board members ensures strategic security decisions are vetted at the appropriate level of authority.
Question 69: A CISO uses Porter's Five Forces model during strategic planning. Which force directly relates to the risk posed by disruptive technology replacing existing security solutions?
- Rivalry among existing competitors
- Threat of new entrants
- Bargaining power of suppliers
- Threat of substitute products (Correct answer)
Correct answer: Threat of substitute products
The threat of substitutes captures the risk that alternative technologies or approaches could render current security tools obsolete.
Question 70: What is the key difference between qualitative and quantitative risk analysis?
- Qualitative is more accurate because it uses expert judgment
- Qualitative uses descriptive categories like High/Medium/Low; quantitative uses numerical financial metrics like ALE (Correct answer)
- Qualitative analysis uses numerical financial values; quantitative uses descriptive ratings
- Quantitative analysis is always preferred because it eliminates subjectivity
Correct answer: Qualitative uses descriptive categories like High/Medium/Low; quantitative uses numerical financial metrics like ALE
Qualitative analysis rates risks using descriptive scales, while quantitative analysis expresses risk in monetary terms such as Annual Loss Expectancy (ALE).
Question 71: Which security control category BEST describes a business continuity plan?
- Deterrent control
- Corrective control (Correct answer)
- Preventive control
- Detective control
Correct answer: Corrective control
A business continuity plan is a corrective control because it is designed to restore operations and recover from a disruptive event after it has occurred.
Question 72: A CISO adopts an 'assume breach' philosophy in strategic planning. This approach PRIMARILY affects which planning element?
- Detection, response, and recovery capability investments (Correct answer)
- Perimeter defense investment levels
- Employee background check frequency
- Physical security posture
Correct answer: Detection, response, and recovery capability investments
Assume breach shifts strategic focus from prevention-only to robust detection, response, and recovery, accepting that perimeter breaches will occur.
Question 73: Under the NIST Cybersecurity Framework, which core function involves developing and implementing activities to identify a cybersecurity incident?
- Protect
- Identify
- Respond
- Detect (Correct answer)
Correct answer: Detect
The Detect function in the NIST CSF focuses on developing and implementing appropriate activities to identify the occurrence of a cybersecurity event.
Question 74: A CISO presents a security strategy to the board but receives pushback that it conflicts with a planned acquisition. This scenario highlights the importance of:
- Stricter access control policies
- Increasing the security budget
- Annual penetration testing
- Integrating security strategy into enterprise strategic planning cycles (Correct answer)
Correct answer: Integrating security strategy into enterprise strategic planning cycles
Security strategy must be synchronized with enterprise planning cycles so that major business events like acquisitions are considered from the outset.
Question 75: Which of the following BEST describes a security strategy's 'strategic objective'?
- A broad, measurable outcome the security program aims to achieve over the planning period (Correct answer)
- A specific technical control to be implemented within 30 days
- An SLA metric in a vendor contract
- A password complexity requirement in a security policy
Correct answer: A broad, measurable outcome the security program aims to achieve over the planning period
Strategic objectives are high-level, measurable outcomes (e.g., 'achieve ISO 27001 certification within 2 years') that guide program direction.
Question 76: A CISO is reviewing third-party risk. Which contractual mechanism BEST ensures the vendor maintains adequate security controls over time?
- Non-disclosure agreement (NDA)
- Right-to-audit clause in the service agreement (Correct answer)
- Service Level Agreement (SLA) defining uptime requirements
- Indemnification clause limiting liability
Correct answer: Right-to-audit clause in the service agreement
A right-to-audit clause gives the organization the contractual right to assess the vendor's security controls periodically, ensuring ongoing compliance with security requirements.
Question 77: What is the PRIMARY benefit of implementing a formal exception management process within a security program?
- It provides a documented, risk-accepted path for business units that cannot immediately comply with policy (Correct answer)
- It reduces the number of security policies needed
- It transfers liability for security incidents to business units
- It allows the security team to ignore policy violations
Correct answer: It provides a documented, risk-accepted path for business units that cannot immediately comply with policy
Exception management balances business agility with risk governance by formally documenting, approving, and tracking deviations from security policy.
Question 78: A CISO is preparing an audit report for the board. Which characteristic is most important for the executive summary?
- Inclusion of all technical details and raw data
- Concise risk-ranked findings with business impact and remediation priorities (Correct answer)
- Detailed statistical analysis of sample populations
- A comprehensive list of all audit procedures performed
Correct answer: Concise risk-ranked findings with business impact and remediation priorities
Executive summaries should present risk-ranked findings with clear business impact and prioritized recommendations to support board-level decision-making.
Question 79: What is the significance of internal controls in risk management?
- They streamline business operations.
- They help to market new products.
- They are used to increase sales revenue.
- They help prevent fraud, errors, and ensure compliance with regulations. (Correct answer)
Correct answer: They help prevent fraud, errors, and ensure compliance with regulations.
Internal controls are vital in risk management as they are the policies, procedures, and practices implemented to safeguard assets, ensure the accuracy of financial data, and promote operational efficiency. They are designed to prevent and detect fraud, errors, and non-compliance with regulations. Effective internal controls strengthen an organization's ability to manage risks and achieve its objectives.
Question 80: Which metric BEST helps a CISO demonstrate the business value of a security program to the board?
- Return on Security Investment (ROSI) (Correct answer)
- Mean time to detect (MTTD) in hours
- Percentage of systems with antivirus installed
- Number of vulnerabilities patched per quarter
Correct answer: Return on Security Investment (ROSI)
ROSI translates security investments into financial terms that resonate with business leadership, demonstrating cost-benefit value.
Question 81: A CISO wants to ensure audit recommendations are implemented on schedule. Which mechanism is most effective?
- Requiring re-audits within 30 days of each finding
- Establishing a formal tracking system with defined owners, due dates, and periodic status reviews (Correct answer)
- Publishing audit results publicly to create accountability pressure
- Delegating follow-up entirely to external auditors
Correct answer: Establishing a formal tracking system with defined owners, due dates, and periodic status reviews
A formal tracking system with assigned owners, deadlines, and status reviews ensures systematic, accountable remediation of audit findings.
Question 82: When presenting the security program's annual report to the board, which content is MOST important to include?
- Detailed firewall rule sets and network diagrams
- Complete list of all CVEs patched during the year
- Technical specifications of all security tools deployed
- Risk posture trends, program accomplishments, and resource gaps tied to business risk (Correct answer)
Correct answer: Risk posture trends, program accomplishments, and resource gaps tied to business risk
Boards need risk posture trends and business-relevant gaps, not technical details, to make informed decisions about security investment.
Question 83: A CISO discovers that an internal audit team lacks independence because its manager reports to the CIO. What is the most appropriate corrective action?
- Outsource all audits to an external firm
- Rotate audit staff annually to reduce bias
- Require auditors to sign independence declarations
- Restructure so the internal audit function reports to the audit committee or board (Correct answer)
Correct answer: Restructure so the internal audit function reports to the audit committee or board
True independence requires the internal audit function to report to the audit committee or board, not to operational management.
Question 84: Which metric defines the maximum amount of data loss an organization can tolerate, expressed in time?
- Maximum Tolerable Downtime (MTD)
- Recovery Time Objective (RTO)
- Service Delivery Objective (SDO)
- Recovery Point Objective (RPO) (Correct answer)
Correct answer: Recovery Point Objective (RPO)
RPO defines the maximum acceptable age of files that must be recovered from backup storage to resume normal operations after a disaster.
Question 85: In strategic planning, 'capability maturity' assessments help a CISO to:
- Satisfy annual audit requirements
- Certify staff competency levels
- Benchmark current security practices against a defined scale to prioritize improvements (Correct answer)
- Identify specific exploited vulnerabilities
Correct answer: Benchmark current security practices against a defined scale to prioritize improvements
Capability maturity models (e.g., CMM, C2M2) measure process maturity on a defined scale and guide investment in areas needing improvement.
Question 86: Which security architecture principle states that a subject should only have the minimum access rights necessary to perform its authorized functions?
- Job rotation
- Least privilege (Correct answer)
- Separation of duties
- Need-to-know
Correct answer: Least privilege
The principle of least privilege limits user and system permissions to the minimum required to accomplish legitimate tasks, reducing the potential damage from errors, attacks, or compromised accounts.
Question 87: Which skill is most critical for effective strategic planning?
- Speed of decision-making
- Communication and stakeholder engagement (Correct answer)
- Individual work preferences
- Technical expertise alone
Correct answer: Communication and stakeholder engagement
Communication and stakeholder engagement are essential because management success depends on effectively coordinating with and influencing others.
Question 88: What does the term 'security architecture roadmap' primarily define in strategic planning?
- Network topology diagrams for current infrastructure
- Vendor contracts for security tools
- Incident response playbooks for known threat vectors
- A prioritized sequence of security initiatives aligned to future-state objectives (Correct answer)
Correct answer: A prioritized sequence of security initiatives aligned to future-state objectives
A security architecture roadmap outlines the phased progression from the current security state to the desired future state.
Question 89: An organization's risk appetite statement should PRIMARILY be defined by:
- The board of directors or executive leadership aligned with business strategy (Correct answer)
- Compliance requirements from applicable regulatory frameworks
- The results of the most recent penetration test
- The CISO based on technical risk tolerance thresholds
Correct answer: The board of directors or executive leadership aligned with business strategy
Risk appetite reflects the organization's willingness to accept risk in pursuit of business objectives and must be set by the board or executive leadership to align with strategic direction.
Question 90: A CCISO certified professional is asked to provide services outside their scope of competence. The CORRECT ethical response is to:
- Decline and refer to a qualified professional (Correct answer)
- Accept and learn as they go
- Accept the work to gain new experience
- Accept but charge a lower rate
Correct answer: Decline and refer to a qualified professional
Ethical practice requires professionals to work within their scope of competence. Accepting work beyond one's qualifications can lead to substandard results and potential harm. Referring to qualified professionals ensures proper service delivery.
Question 91: When prioritizing strategic security initiatives, a CISO should PRIMARILY consider:
- Risk reduction value relative to business impact and available resources (Correct answer)
- Regulatory penalties alone
- Vendor recommendations and product roadmaps
- Industry peers' technology choices
Correct answer: Risk reduction value relative to business impact and available resources
Initiative prioritization must weigh risk reduction potential against business impact and resource constraints for maximum strategic value.
Question 92: What distinguishes a EC-Council Certified CISO certified professional from a non-certified practitioner?
- Certified professionals always have more years of experience
- Certified professionals exclusively work in larger organizations
- Certification validates competency through standardized assessment against established benchmarks (Correct answer)
- There is no meaningful difference in competency
Correct answer: Certification validates competency through standardized assessment against established benchmarks
Certification provides objective validation of competency through standardized assessment. While non-certified practitioners may be skilled, certification offers verified evidence that a professional meets established benchmarks for knowledge and performance.
Question 93: A CISO reviewing IAM metrics notices that 15% of user accounts have not been accessed in over 90 days. What is the most appropriate immediate action?
- Increase password complexity requirements for all users
- Reset passwords on all inactive accounts and notify users
- Immediately delete all inactive accounts without further review
- Disable or lock inactive accounts pending business justification review and formal reactivation process (Correct answer)
Correct answer: Disable or lock inactive accounts pending business justification review and formal reactivation process
Dormant accounts represent an attack surface; disabling them pending review follows least-privilege principles while avoiding accidental deletion of potentially needed accounts such as seasonal or project-based users.
Question 94: A CISO is negotiating a cloud services contract. Which provision is MOST important to address data residency requirements?
- Contractual specification of geographic regions where data may be stored and processed (Correct answer)
- Vendor's marketing content rights
- Uptime SLA guarantees
- Auto-renewal clauses
Correct answer: Contractual specification of geographic regions where data may be stored and processed
Specifying permissible geographic regions for data storage and processing in the contract directly addresses data residency and regulatory compliance requirements.
Question 95: When developing a security program charter, which element is MOST critical to include to ensure executive sponsorship?
- Specific vulnerability remediation timelines
- List of all security tools and vendors
- Defined authority, scope, and accountability of the security function (Correct answer)
- Detailed technical architecture diagrams
Correct answer: Defined authority, scope, and accountability of the security function
A charter must define authority and scope so that executives understand and formally delegate responsibility to the CISO.
Question 96: How does the CCISO body of knowledge relate to daily professional practice?
- It provides the foundational framework that guides decision-making and standard practices (Correct answer)
- It only applies during certification exams
- It is theoretical and has limited practical application
- It is relevant only for academic research
Correct answer: It provides the foundational framework that guides decision-making and standard practices
The body of knowledge provides the foundational framework of principles, standards, and best practices that professionals use to guide their daily decision-making, ensure consistent quality, and maintain alignment with industry standards.
Question 97: What is the PRIMARY purpose of a security steering committee in an enterprise?
- To manage day-to-day incident response
- To provide executive oversight and strategic direction for the security program (Correct answer)
- To approve all firewall rule changes
- To perform hands-on security testing
Correct answer: To provide executive oversight and strategic direction for the security program
A security steering committee provides cross-functional executive governance, ensuring the security program aligns with business strategy.
Question 98: A CISO is evaluating the maturity of the security program using CMMI. The organization consistently follows defined, documented processes but does not yet measure process effectiveness. Which maturity level does this represent?
- Level 1 – Initial
- Level 3 – Defined (Correct answer)
- Level 4 – Quantitatively Managed
- Level 2 – Managed
Correct answer: Level 3 – Defined
CMMI Level 3 (Defined) means processes are standardized and documented organization-wide, but measurement and control come at Level 4.
Question 99: Which BC element addresses how the organization will manage communications with media and the public during a major disruption?
- Occupant Emergency Plan
- Facilities Recovery Plan
- IT Disaster Recovery Runbook
- Public Relations and Media Communications Plan (Correct answer)
Correct answer: Public Relations and Media Communications Plan
A Public Relations and Media Communications Plan provides pre-approved messaging, spokesperson assignments, and protocols for managing external communications during a crisis.
Question 100: What is the most effective approach to vendor management in the CCISO field?
- Maintaining the status quo
- Reactive problem-solving
- Following competitors
- Systematic planning and continuous improvement (Correct answer)
Correct answer: Systematic planning and continuous improvement
Systematic planning combined with continuous improvement ensures sustainable success and allows for proactive management of challenges.
Question 101: Which document BEST communicates the organization's commitment to information security to both internal and external stakeholders?
- Risk Register
- System Security Plan (SSP)
- Business Continuity Plan (BCP)
- Information Security Policy (Correct answer)
Correct answer: Information Security Policy
An Information Security Policy is the high-level governance document that formally declares the organization's commitment and sets the tone from leadership.
Question 102: A company's board asks a CISO about Sarbanes-Oxley (SOX) Section 404 requirements. What does Section 404 primarily mandate?
- Mandatory cybersecurity incident disclosure within 72 hours
- CEO/CFO certification of cybersecurity posture
- Annual penetration testing of financial systems
- Management assessment of internal controls over financial reporting (Correct answer)
Correct answer: Management assessment of internal controls over financial reporting
SOX Section 404 requires management to assess and report on the effectiveness of internal controls over financial reporting, with auditor attestation.
Question 103: In the context of intellectual property law, which type of protection applies to software source code and documentation by default upon creation?
- Patent
- Trademark
- Trade secret
- Copyright (Correct answer)
Correct answer: Copyright
Copyright protection attaches automatically to original works including software source code the moment they are created and fixed in a tangible medium.
Question 104: What security architectural pattern does a Content Delivery Network (CDN) with DDoS mitigation capability primarily implement?
- Zero-knowledge encryption of cached content
- Data loss prevention at the edge
- Distributed traffic absorption and scrubbing that protects origin servers by dispersing attack traffic across global points of presence (Correct answer)
- Multi-factor authentication for content access
Correct answer: Distributed traffic absorption and scrubbing that protects origin servers by dispersing attack traffic across global points of presence
CDNs with DDoS mitigation absorb and filter attack traffic at globally distributed edge nodes, preventing volumetric attacks from overwhelming origin infrastructure.
Question 105: In CCISO practice, what is the best approach to quality improvement in business continuity?
- Wait for problems to occur before acting
- Use data-driven methods with measurable outcomes (Correct answer)
- Copy what other organizations do without analysis
- Make changes without measuring results
Correct answer: Use data-driven methods with measurable outcomes
Data-driven quality improvement with measurable outcomes ensures that changes actually produce the intended improvements and can be verified.
Question 106: In EC-Council Certified CISO practice, what is the FIRST step when a safety hazard is identified in the workplace?
- Continue working and report at end of shift
- Immediately secure the area and report the hazard (Correct answer)
- Document it for the next safety audit
- Wait for a supervisor to notice the issue
Correct answer: Immediately secure the area and report the hazard
When a safety hazard is identified, the immediate priority is to secure the area to prevent injury and report the hazard through proper channels. Delaying action increases the risk of incidents.
Question 107: Which statement BEST describes the relationship between EC-Council Certified CISO certification requirements and industry evolution?
- Changes only occur when government mandates new requirements
- Certification requirements never change once established
- Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards (Correct answer)
- Requirements become less stringent over time
Correct answer: Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards
Certification requirements evolve to keep pace with advances in professional knowledge, technological developments, and changes in practice standards. This ensures that certified professionals remain current and competent in a changing professional landscape.
Question 108: An attacker used compromised credentials obtained via credential stuffing to access a customer portal. After containment, which remediation action has the highest long-term impact on preventing recurrence?
- Increasing password minimum length to 10 characters
- Resetting only the compromised accounts
- Implementing multi-factor authentication across all customer-facing portals (Correct answer)
- Blocking the attacker's IP addresses permanently
Correct answer: Implementing multi-factor authentication across all customer-facing portals
MFA prevents credential stuffing attacks from succeeding even when valid credentials are obtained, addressing the root cause rather than symptoms.
Question 109: During a major security incident, the CEO asks the CISO for a real-time status update every 30 minutes. What is the BEST way to handle this without compromising the IR team's effectiveness?
- Designate a communications liaison to provide structured executive briefings on a defined schedule while the IR team focuses on response (Correct answer)
- Assign the CISO to provide updates personally, pulling them away from oversight duties
- Halt all IR activities during briefing periods to ensure accuracy
- Refuse executive briefings until the incident is fully resolved
Correct answer: Designate a communications liaison to provide structured executive briefings on a defined schedule while the IR team focuses on response
A designated communications liaison allows executive stakeholders to receive regular updates without disrupting the IR team's focus on containment and investigation activities.
Question 110: A CISO is preparing a 5-year security strategy immediately following a major data breach. Which element should receive HIGHEST priority in the early phases?
- Renegotiating all vendor contracts
- Immediate capability gaps in detection and response exposed by the breach (Correct answer)
- Restructuring the entire security organization
- Long-term technology procurement planning
Correct answer: Immediate capability gaps in detection and response exposed by the breach
Post-breach strategic planning must first address the specific capability failures exposed by the incident before focusing on longer-term transformation.
Question 111: Which type of audit opinion is issued when auditors cannot obtain sufficient appropriate evidence to form a conclusion?
- Disclaimer of opinion (Correct answer)
- Qualified opinion
- Adverse opinion
- Unmodified opinion
Correct answer: Disclaimer of opinion
A disclaimer of opinion is issued when the auditor is unable to obtain sufficient evidence, making it impossible to express any audit opinion.
Question 112: What is the MOST important reason for EC-Council Certified CISO professionals to maintain continuing education?
- To stay current with evolving standards, practices, and regulations (Correct answer)
- To accumulate credentials for personal prestige
- To increase billing rates
- To satisfy employer preferences
Correct answer: To stay current with evolving standards, practices, and regulations
Continuing education ensures professionals remain current with evolving industry standards, best practices, and regulatory requirements. This directly impacts the quality of service provided and maintains public trust in the profession.
Question 113: Which risk management approach is MOST effective for CCISO professionals when evaluating potential workplace hazards?
- Delegating all safety decisions to management
- Relying solely on historical accident data
- Reactive analysis after incidents occur
- Proactive hazard identification and assessment (Correct answer)
Correct answer: Proactive hazard identification and assessment
Proactive hazard identification and assessment allows professionals to identify and mitigate risks before incidents occur, which is far more effective than reactive approaches that only address problems after they happen.
Question 114: An organization is implementing security metrics. Which characteristic is MOST important for a metric to be useful for security management decisions?
- The metric should be actionable and tied to a specific decision or outcome (Correct answer)
- The metric should be self-reported by the team being measured
- The metric should track the largest possible volume of security events
- The metric should be technically complex to demonstrate program sophistication
Correct answer: The metric should be actionable and tied to a specific decision or outcome
Effective security metrics must be actionable, meaning they provide information that can drive a specific management decision or corrective action.
Question 115: A CISO reviewing a strategic plan notices security goals are not linked to any business outcomes. This represents a failure of:
- Change management
- Business-IT alignment (Correct answer)
- Vulnerability management
- Incident classification
Correct answer: Business-IT alignment
Business-IT alignment ensures security objectives directly support and are traceable to organizational business outcomes and priorities.
Question 116: A CISO must understand the concept of 'safe harbor' in data privacy law. In the context of GDPR, which mechanism serves as a safe harbor for transferring personal data to the US?
- Binding Safe Harbor Agreement
- Standard Contractual Clauses (SCCs) (Correct answer)
- Privacy Shield (currently valid)
- APEC Cross-Border Privacy Rules
Correct answer: Standard Contractual Clauses (SCCs)
Following the invalidation of Privacy Shield by Schrems II, Standard Contractual Clauses (SCCs) are the primary mechanism for lawful EU-to-US personal data transfers.
Question 117: During a vendor risk assessment, the security team discovers a critical supplier uses the same IT infrastructure for multiple clients with no logical separation. This BEST represents which type of risk?
- Operational risk
- Regulatory risk
- Concentration risk (Correct answer)
- Reputational risk
Correct answer: Concentration risk
Concentration risk arises when a vendor's shared infrastructure creates potential exposure where a breach affecting one client could impact others.
Question 118: A CISO wants to quantify the financial return of security controls to justify budget increases. The MOST appropriate method is:
- Return on Security Investment (ROSI) analysis using risk reduction and loss expectancy (Correct answer)
- Number of security incidents closed per quarter
- Headcount ratio of security staff to total employees
- CVSS scoring of identified vulnerabilities
Correct answer: Return on Security Investment (ROSI) analysis using risk reduction and loss expectancy
ROSI calculates expected loss reduction against control cost, providing a financial justification framework for security investment decisions.
Question 119: An insider threat incident is discovered involving a privileged administrator who copied sensitive data to personal cloud storage over six months. Which IR process failure allowed the prolonged activity?
- Absence of a vulnerability management program
- Failure to conduct annual security awareness training
- Lack of user and entity behavior analytics (UEBA) or privileged user monitoring controls (Correct answer)
- Missing patch management procedures
Correct answer: Lack of user and entity behavior analytics (UEBA) or privileged user monitoring controls
UEBA and privileged user monitoring detect anomalous behavior patterns over time, which are necessary to catch slow-burn insider threats that evade signature-based detection.
Question 120: When a CISO develops security strategy for an organization operating in a heavily regulated industry, regulatory compliance requirements should be treated as:
- Optional guidelines subject to cost-benefit analysis
- Responsibility of the legal department, not the CISO
- The sole driver of the security strategy
- A baseline constraint, with risk-driven priorities built above that floor (Correct answer)
Correct answer: A baseline constraint, with risk-driven priorities built above that floor
Compliance sets a minimum required baseline; effective security strategy layers risk-driven controls above that floor to address actual threats.
Question 121: In a segmented network architecture, what is the PRIMARY purpose of a demilitarized zone (DMZ)?
- To isolate workstations from servers
- To host internal databases away from the internet
- To provide a buffer zone between untrusted external networks and trusted internal networks (Correct answer)
- To store encryption keys securely
Correct answer: To provide a buffer zone between untrusted external networks and trusted internal networks
A DMZ acts as a buffer zone that separates an organization's internal network from untrusted external networks, hosting publicly accessible services while protecting internal resources.
Question 122: A CISO is designing security architecture for a DevSecOps pipeline. At which stage should static application security testing (SAST) be integrated for MAXIMUM effectiveness?
- Only during the final pre-release security review
- After deployment to production
- During the coding/build phase, so vulnerabilities are detected and remediated before they progress through the pipeline (Correct answer)
- Exclusively during penetration testing engagements
Correct answer: During the coding/build phase, so vulnerabilities are detected and remediated before they progress through the pipeline
Integrating SAST during the coding and build phases follows the 'shift left' principle, detecting vulnerabilities at the cheapest point in the SDLC before they propagate to later, more expensive stages.
Question 123: A CISO incorporates lessons learned from peer organizations' breaches into the strategic plan. This practice is an example of:
- Competitive intelligence gathering
- Benchmarking operational metrics
- Cyber threat intelligence integration into strategic planning (Correct answer)
- Supply chain risk management
Correct answer: Cyber threat intelligence integration into strategic planning
Using external breach intelligence to inform strategic decisions is a core application of cyber threat intelligence at the strategic planning level.
Question 124: Which approach BEST describes integrating security into an organization's SDLC?
- Performing penetration testing only before production releases
- Embedding security requirements, reviews, and testing at every phase of development (Correct answer)
- Requiring developers to pass a security certification
- Installing WAFs in front of all applications
Correct answer: Embedding security requirements, reviews, and testing at every phase of development
A DevSecOps approach embeds security throughout all SDLC phases rather than treating it as a gate at the end.
Question 125: Which strategy BEST mitigates the risk of vendor personnel becoming a conduit for social engineering attacks against the organization?
- Limiting vendor contracts to fixed-price agreements
- Conducting weekly vendor invoice reviews
- Ensuring vendors maintain their own separate IT infrastructure
- Requiring vendor personnel to complete security awareness training aligned with organizational policies (Correct answer)
Correct answer: Requiring vendor personnel to complete security awareness training aligned with organizational policies
Security awareness training for vendor personnel aligned to organizational policies reduces the likelihood of vendor staff being successfully targeted or manipulated in social engineering attacks.
Question 126: In CCISO practice, what is the primary purpose of strategic planning?
- To reduce workforce
- To align resources with goals and anticipate challenges (Correct answer)
- To create paperwork
- To satisfy external auditors
Correct answer: To align resources with goals and anticipate challenges
Strategic planning aligns organizational resources with goals and helps anticipate challenges before they become critical issues.
Question 127: Which approach ensures that security strategic planning remains relevant as the threat landscape evolves?
- Embedding continuous threat intelligence review cycles into strategic planning (Correct answer)
- Outsourcing all strategic updates to a consulting firm
- Relying solely on compliance mandates to trigger strategy updates
- Locking the strategy document and revisiting only every 5 years
Correct answer: Embedding continuous threat intelligence review cycles into strategic planning
Incorporating ongoing threat intelligence into planning cycles ensures the strategy adapts to emerging risks without waiting for a full planning refresh.
Question 128: A vendor management policy requires that all vendors with access to sensitive systems undergo background checks on their employees. This control PRIMARILY addresses which risk?
- Regulatory non-compliance
- Data residency violations
- License compliance issues
- Insider threat from vendor personnel (Correct answer)
Correct answer: Insider threat from vendor personnel
Background checks on vendor employees mitigate insider threat risk by vetting individuals who may have access to sensitive organizational systems.
Question 129: Which security architecture concept involves distributing security controls across multiple layers so that if one layer fails, subsequent layers continue to provide protection?
- Least privilege
- Need-to-know
- Defense-in-depth (Correct answer)
- Separation of duties
Correct answer: Defense-in-depth
Defense-in-depth is a layered security strategy where multiple overlapping security controls are deployed so that failure of a single control does not compromise the overall security posture.
Question 130: What documentation is MOST critical to maintain for safety compliance in the EC-Council Certified CISO field?
- Client marketing preferences
- Incident reports, training records, and inspection logs (Correct answer)
- Employee vacation schedules
- Annual revenue reports
Correct answer: Incident reports, training records, and inspection logs
Incident reports, training records, and inspection logs are essential safety documentation. They demonstrate compliance with safety regulations, track training completion, and provide evidence of systematic hazard management.
Question 131: A CISO wants to reduce the impact of a critical vendor going bankrupt. Which strategy is MOST effective for ensuring business continuity?
- Develop an alternative vendor or escrow arrangement (Correct answer)
- Negotiate lower contract pricing
- Require the vendor to purchase insurance
- Increase the frequency of invoice reviews
Correct answer: Develop an alternative vendor or escrow arrangement
Maintaining an alternative vendor or software escrow arrangement ensures continuity of critical services if the primary vendor ceases operations.
Question 132: What is the key difference between authentication and authorization in the context of IAM?
- Authentication verifies the identity of a user, while authorization determines what that verified identity is permitted to do (Correct answer)
- Authentication is performed by humans while authorization is automated
- Authentication is optional while authorization is always mandatory
- Authentication applies to external users while authorization applies to internal users
Correct answer: Authentication verifies the identity of a user, while authorization determines what that verified identity is permitted to do
Authentication answers 'who are you?' by verifying identity credentials, while authorization answers 'what are you allowed to do?' by enforcing access control policies for the authenticated identity.
Question 133: A multinational company undergoes an M&A transaction. From a legal and compliance standpoint, which due diligence area is most critical from a CISO's perspective?
- Assessing inherited cybersecurity liabilities and regulatory obligations (Correct answer)
- Auditing the target's HR policies
- Evaluating the target's hardware asset inventory
- Reviewing the target's marketing strategy
Correct answer: Assessing inherited cybersecurity liabilities and regulatory obligations
During M&A due diligence, the acquiring company must assess inherited cybersecurity vulnerabilities, data breaches, regulatory violations, and compliance obligations of the target.
Question 134: Which scenario BEST illustrates misalignment between security strategy and business strategy?
- The security team blocks a merger due to undisclosed cyber risks (Correct answer)
- Security KPIs are reported in quarterly business reviews
- A CISO hires staff to support a planned cloud migration
- Security budget increases alongside revenue growth
Correct answer: The security team blocks a merger due to undisclosed cyber risks
If security risks from a merger are not surfaced until they cause a blockage, the security program is reactive rather than integrated with business strategy.
Question 135: Which metric is most useful for evaluating program effectiveness in CCISO?
- Number of staff involved
- Number of meetings held
- Outcome-based performance indicators (Correct answer)
- Amount of money spent
Correct answer: Outcome-based performance indicators
Outcome-based performance indicators directly measure whether the program is achieving its intended results and goals.
Question 136: Which metric is most useful for evaluating program effectiveness in CCISO?
- Amount of money spent
- Outcome-based performance indicators (Correct answer)
- Number of staff involved
- Number of meetings held
Correct answer: Outcome-based performance indicators
Outcome-based performance indicators directly measure whether the program is achieving its intended results and goals.
Question 137: When developing a compliance program, which approach ensures that controls satisfy multiple regulatory requirements simultaneously?
- Sequentially achieving one certification before starting the next
- Outsourcing each regulation's compliance to a different vendor
- A unified control framework mapped to multiple regulatory requirements (Correct answer)
- Siloed compliance with separate control sets for each regulation
Correct answer: A unified control framework mapped to multiple regulatory requirements
A unified control framework with crosswalk mappings allows a single control to satisfy multiple regulatory requirements, reducing redundancy and cost.
Question 138: A ransomware attack has encrypted critical operational systems. The IR team recommends paying the ransom to restore operations quickly. What should the CISO do FIRST?
- Issue a public statement accepting responsibility for the breach
- Approve the payment to minimize downtime
- Restore from backup without notifying law enforcement
- Consult legal counsel and law enforcement before authorizing payment (Correct answer)
Correct answer: Consult legal counsel and law enforcement before authorizing payment
Legal counsel must assess sanctions exposure and regulatory obligations, and law enforcement engagement may be legally required before any ransom payment is made.
Question 139: What is the recommended approach when managing conflicting priorities in CCISO?
- Prioritize based on impact and urgency (Correct answer)
- Address them in alphabetical order
- Delegate all decisions upward
- Ignore lower-priority items
Correct answer: Prioritize based on impact and urgency
Prioritizing based on impact and urgency ensures the most critical issues receive attention first while maintaining progress on other goals.
Question 140: What is the most effective approach to financial management in the CCISO field?
- Following competitors
- Systematic planning and continuous improvement (Correct answer)
- Maintaining the status quo
- Reactive problem-solving
Correct answer: Systematic planning and continuous improvement
Systematic planning combined with continuous improvement ensures sustainable success and allows for proactive management of challenges.
Question 141: An organization is expanding globally and must manage security across multiple regulatory jurisdictions. What is the MOST effective approach?
- Develop a baseline security framework and layer jurisdiction-specific controls on top (Correct answer)
- Rely on local legal counsel to manage all compliance requirements
- Create entirely separate security programs for each country
- Apply the strictest single jurisdiction's requirements globally
Correct answer: Develop a baseline security framework and layer jurisdiction-specific controls on top
A baseline with layered jurisdiction-specific controls efficiently meets multiple regulatory requirements without duplicating the entire security program.
Question 142: A CISO needs to align the security program with business objectives. Which framework is MOST appropriate for mapping security controls to business goals?
- COBIT 2019 (Correct answer)
- ISO 27001 Annex A
- HIPAA Security Rule
- PCI DSS
Correct answer: COBIT 2019
COBIT 2019 is specifically designed to align IT governance, including security, with overall enterprise business objectives.
Question 143: A CISO is asked to develop a security metrics dashboard for the CFO. Which metric most directly links security investment to financial performance?
- Number of vulnerabilities patched monthly
- Cost per security incident and reduction in ALE over time (Correct answer)
- Percentage of employees completing security awareness training
- Mean Time to Detect (MTTD) security incidents
Correct answer: Cost per security incident and reduction in ALE over time
Cost per incident and ALE reduction directly connect security program performance to financial outcomes, making them most relevant to CFO-level reporting.
Question 144: What is the primary consideration when implementing changes to security architecture?
- Impact assessment and change management (Correct answer)
- Vendor preference
- Speed of implementation
- Personal convenience
Correct answer: Impact assessment and change management
Impact assessment and proper change management ensure that modifications do not introduce unexpected problems or service disruptions.
Question 145: Which metric type directly demonstrates the business value of security investments to executive stakeholders?
- Number of vulnerability scans completed
- Firewall rule count
- Cost avoidance from prevented incidents (Correct answer)
- Patch compliance percentage
Correct answer: Cost avoidance from prevented incidents
Cost avoidance metrics translate security activities into financial terms that resonate with business leadership and justify investment.
Question 146: Which IAM process ensures that a new employee receives only the access rights necessary for their specific role on their first day of employment?
- Privilege escalation review
- Joiner-Mover-Leaver (JML) provisioning — specifically the joiner workflow (Correct answer)
- Emergency access break-glass procedure
- Access recertification
Correct answer: Joiner-Mover-Leaver (JML) provisioning — specifically the joiner workflow
The JML framework governs the identity lifecycle: the joiner process provisions appropriate role-based access at onboarding, the mover process adjusts access during role changes, and the leaver process revokes access at offboarding.
Question 147: Which statement BEST describes the relationship between EC-Council Certified CISO certification requirements and industry evolution?
- Requirements become less stringent over time
- Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards (Correct answer)
- Changes only occur when government mandates new requirements
- Certification requirements never change once established
Correct answer: Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards
Certification requirements evolve to keep pace with advances in professional knowledge, technological developments, and changes in practice standards. This ensures that certified professionals remain current and competent in a changing professional landscape.
Question 148: Under the ISACA IT Audit framework, which term describes the root cause of a control deficiency?
- Effect
- Cause (Correct answer)
- Condition
- Criteria
Correct answer: Cause
In audit finding structure, 'cause' identifies why the control deficiency exists, helping management address the underlying problem rather than just the symptom.
Question 149: What is the purpose of the post-incident review?
- To evaluate the response and improve future incident management. (Correct answer)
- To notify the press about the incident.
- To assess financial damages.
- To assign blame for the incident.
Correct answer: To evaluate the response and improve future incident management.
The purpose of the post-incident review is to evaluate the effectiveness of the incident response process and identify areas for improvement. This critical step involves analyzing what went well, what could have been done better, and what lessons were learned. The insights gained from this review are used to refine incident management plans, improve security controls, and enhance future response capabilities.
Question 150: A CISO is preparing a five-year security roadmap with associated budget projections. Which financial planning technique accounts for the decreasing value of future spending in today's dollars?
- Sensitivity analysis
- Earned value management
- Break-even analysis
- Discounted cash flow (DCF) analysis (Correct answer)
Correct answer: Discounted cash flow (DCF) analysis
Discounted cash flow analysis applies discount rates to future cash outflows to express them in present value terms, enabling accurate multi-year financial comparison.
Question 151: A CISO is conducting a gap analysis between current security controls and ISO 27001 requirements. What audit technique is being applied?
- Compliance testing (Correct answer)
- Benchmarking
- Control self-assessment
- Substantive testing
Correct answer: Compliance testing
Comparing existing controls against a standard's requirements is compliance (or conformance) testing, which determines whether controls meet defined criteria.
EC-Council Certified CISO (CCISO) Exam
The CCISO certification recognizes the experience and knowledge required to develop and execute an information security management strategy at the executive level.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds