← All CCISO Flashcard Decks

Mixed Deck — All CCISO Topics Flashcards

100 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CCISO Topics flashcards as text
  1. An organization uses a hot site for disaster recovery. What distinguishes a hot site from a warm site?

    Answer: A hot site has fully operational systems with real-time data replication

    A hot site is a fully equipped and operational duplicate facility with real-time or near-real-time data replication, enabling near-immediate failover.

  2. What is the most effective approach to vendor management in the CCISO field?

    Answer: Systematic planning and continuous improvement

    Systematic planning combined with continuous improvement ensures sustainable success and allows for proactive management of challenges.

  3. During strategic planning, a CISO identifies that a proposed cloud migration increases residual risk beyond the board's appetite. The BEST response is to:

    Answer: Escalate findings and propose risk treatment options to leadership

    The CISO should surface findings to decision-makers and present treatment options so leadership can make informed risk-acceptance decisions.

  4. A CISO notices that control effectiveness reviews are only performed annually. What is the PRIMARY risk of infrequent control assessments?

    Answer: Controls may become ineffective due to environmental changes without detection

    Infrequent control assessments create a window where controls degraded by system changes, personnel turnover, or new threats go undetected, increasing residual risk.

  5. Which concept refers to the point beyond which a business function cannot recover and the organization would cease to operate viably?

    Answer: Maximum Tolerable Downtime (MTD)

    MTD (also called Maximum Tolerable Period of Disruption) is the maximum time a business function can be unavailable before the organization suffers irreversible harm.

  6. What is the key benefit of evidence-based decision making in CCISO management?

    Answer: It improves accuracy and reduces bias in decisions

    Evidence-based decision making uses data and research to improve the accuracy of decisions and reduce the influence of personal bias.

  7. What is the PRIMARY purpose of obtaining CCISO certification in EC-Council Certified CISO?

    Answer: To demonstrate verified competency and adherence to professional standards

    Professional certification demonstrates that an individual has met established competency standards through verified assessment. It provides assurance to employers, clients, and the public that the certified professional possesses the knowledge and skills required for competent practice.

  8. Which metric is most useful for evaluating program effectiveness in CCISO?

    Answer: Outcome-based performance indicators

    Outcome-based performance indicators directly measure whether the program is achieving its intended results and goals.

  9. Under the CCISO exam framework, which domain most directly encompasses Identity and Access Management as a core competency area?

    Answer: Domain 3: Security Program Management & Operations

    Domain 3 covers security program management and operations, which includes implementing and overseeing controls such as IAM as part of day-to-day security operations.

  10. A CISO needs to align the security program with business objectives. Which framework is MOST appropriate for mapping security controls to business goals?

    Answer: COBIT 2019

    COBIT 2019 is specifically designed to align IT governance, including security, with overall enterprise business objectives.

  11. What distinguishes a EC-Council Certified CISO certified professional from a non-certified practitioner?

    Answer: Certification validates competency through standardized assessment against established benchmarks

    Certification provides objective validation of competency through standardized assessment. While non-certified practitioners may be skilled, certification offers verified evidence that a professional meets established benchmarks for knowledge and performance.

  12. Which authentication factor is classified as "something you are"?

    Answer: Biometric data

    Biometric data such as fingerprints, facial recognition, or retinal scans represents the "something you are" authentication factor.

  13. A CISO wants to quantify the financial return of security controls to justify budget increases. The MOST appropriate method is:

    Answer: Return on Security Investment (ROSI) analysis using risk reduction and loss expectancy

    ROSI calculates expected loss reduction against control cost, providing a financial justification framework for security investment decisions.

  14. When conducting a risk assessment for CCISO operations, which factor should receive the HIGHEST priority?

    Answer: Probability and severity of potential harm

    The probability and severity of potential harm are the primary factors in risk assessment. While cost and convenience are considerations, they should never override the assessment of how likely an incident is and how severe its consequences could be.

  15. A CISO must present the security program's value to the board. Which metric BEST demonstrates the effectiveness of security controls from a business risk perspective?

    Answer: Reduction in risk exposure measured in dollar value

    Boards understand financial risk; expressing risk reduction in dollar value directly connects security investments to business outcomes they can evaluate.

  16. When developing a risk treatment plan, which element is ESSENTIAL to include to ensure accountability and track progress?

    Answer: Named ownership, target completion dates, and success criteria for each action

    A risk treatment plan must assign clear ownership, deadlines, and measurable success criteria so that progress can be tracked and accountability maintained.

  17. The principle of least privilege in IAM requires that users be granted:

    Answer: Access only to the resources and data necessary to perform their assigned job functions

    Least privilege minimizes the attack surface by limiting user permissions to only what is required for their specific role, reducing risk from insider threats and compromised accounts.

  18. Which security architecture concept involves distributing security controls across multiple layers so that if one layer fails, subsequent layers continue to provide protection?

    Answer: Defense-in-depth

    Defense-in-depth is a layered security strategy where multiple overlapping security controls are deployed so that failure of a single control does not compromise the overall security posture.

  19. Multi-Factor Authentication (MFA) requires users to present verification from at least how many distinct authentication factor categories?

    Answer: Two or more factors from different categories

    MFA requires at least two distinct factor categories (e.g., something you know plus something you have), making authentication significantly more resistant to credential theft.

  20. A CISO must understand the concept of 'safe harbor' in data privacy law. In the context of GDPR, which mechanism serves as a safe harbor for transferring personal data to the US?

    Answer: Standard Contractual Clauses (SCCs)

    Following the invalidation of Privacy Shield by Schrems II, Standard Contractual Clauses (SCCs) are the primary mechanism for lawful EU-to-US personal data transfers.