EC-Council Certified CISO (CCISO) Exam — Questions and Answers
Question 1: Which role is typically responsible for declaring a disaster and formally activating the Business Continuity Plan?
- The IT Help Desk Manager
- The Crisis Management Team or designated executive authority (Correct answer)
- Any employee who witnesses the incident
- The Chief Information Security Officer exclusively
Correct answer: The Crisis Management Team or designated executive authority
Formal disaster declaration authority is granted to a Crisis Management Team or a designated senior executive to ensure consistent, authorized activation of the BCP.
Question 2: A CISO discovers that shadow IT spending on unsanctioned SaaS tools totals $1.2M annually. What is the primary financial governance risk this presents?
- Violation of software licensing agreements only
- Unmanaged vendor risk, data exposure, and lack of budgetary control outside procurement oversight (Correct answer)
- Excessive consumption of network bandwidth
- Overspending on redundant security tools
Correct answer: Unmanaged vendor risk, data exposure, and lack of budgetary control outside procurement oversight
Shadow IT creates financial governance failures including uncontrolled vendor risk, data security exposure, and spending that bypasses procurement controls and budget accountability.
Question 3: A CISO incorporates lessons learned from peer organizations' breaches into the strategic plan. This practice is an example of:
- Supply chain risk management
- Cyber threat intelligence integration into strategic planning (Correct answer)
- Competitive intelligence gathering
- Benchmarking operational metrics
Correct answer: Cyber threat intelligence integration into strategic planning
Using external breach intelligence to inform strategic decisions is a core application of cyber threat intelligence at the strategic planning level.
Question 4: Which network security device inspects traffic at the application layer and can make forwarding decisions based on the content of HTTP requests?
- Web Application Firewall (WAF) (Correct answer)
- Network Address Translator (NAT)
- Stateful firewall
- Packet-filtering router
Correct answer: Web Application Firewall (WAF)
A WAF operates at Layer 7 and inspects HTTP/HTTPS content to detect and block application-layer attacks like SQL injection and XSS.
Question 5: A CISO reviewing a strategic plan notices security goals are not linked to any business outcomes. This represents a failure of:
- Incident classification
- Vulnerability management
- Change management
- Business-IT alignment (Correct answer)
Correct answer: Business-IT alignment
Business-IT alignment ensures security objectives directly support and are traceable to organizational business outcomes and priorities.
Question 6: A CISO notices that control effectiveness reviews are only performed annually. What is the PRIMARY risk of infrequent control assessments?
- Annual assessments are too costly for most security budgets
- Employees may lose familiarity with security policies and procedures
- Regulatory penalties for non-compliance with assessment schedules
- Controls may become ineffective due to environmental changes without detection (Correct answer)
Correct answer: Controls may become ineffective due to environmental changes without detection
Infrequent control assessments create a window where controls degraded by system changes, personnel turnover, or new threats go undetected, increasing residual risk.
Question 7: What is the purpose of the post-incident review?
- To notify the press about the incident.
- To assign blame for the incident.
- To assess financial damages.
- To evaluate the response and improve future incident management. (Correct answer)
Correct answer: To evaluate the response and improve future incident management.
The purpose of the post-incident review is to evaluate the effectiveness of the incident response process and identify areas for improvement. This critical step involves analyzing what went well, what could have been done better, and what lessons were learned. The insights gained from this review are used to refine incident management plans, improve security controls, and enhance future response capabilities.
Question 8: An organization implements PKI to manage digital certificates. Which entity is responsible for issuing and revoking certificates within the PKI hierarchy?
- Certificate Authority (CA) (Correct answer)
- Online Certificate Status Protocol (OCSP)
- Registration Authority (RA)
- Certificate Revocation List (CRL)
Correct answer: Certificate Authority (CA)
The CA is the trusted entity that issues digital certificates and maintains revocation records within the PKI trust hierarchy.
Question 9: A CISO is evaluating whether to implement a new security control. The cost of the control is $50,000 annually and the ALE before the control is $120,000. The ALE after the control is $40,000. What is the value of implementing the control?
- $70,000 net benefit
- $80,000 net benefit
- $120,000 net benefit
- $30,000 net benefit (Correct answer)
Correct answer: $30,000 net benefit
The control saves $80,000 (ALE reduction from $120K to $40K) but costs $50,000, yielding a net benefit of $30,000 annually.
Question 10: What is the key difference between qualitative and quantitative risk analysis?
- Quantitative analysis is always preferred because it eliminates subjectivity
- Qualitative analysis uses numerical financial values; quantitative uses descriptive ratings
- Qualitative is more accurate because it uses expert judgment
- Qualitative uses descriptive categories like High/Medium/Low; quantitative uses numerical financial metrics like ALE (Correct answer)
Correct answer: Qualitative uses descriptive categories like High/Medium/Low; quantitative uses numerical financial metrics like ALE
Qualitative analysis rates risks using descriptive scales, while quantitative analysis expresses risk in monetary terms such as Annual Loss Expectancy (ALE).
Question 11: What role does documentation play in CCISO compliance?
- It replaces practical competency
- It provides evidence of adherence to standards (Correct answer)
- It is optional
- It is only needed for audits
Correct answer: It provides evidence of adherence to standards
Documentation provides verifiable evidence that standards and regulations are being followed, serving as proof of compliance.
Question 12: What role does stakeholder involvement play in incident response?
- It increases system efficiency.
- It ensures that decisions are made without the involvement of key people.
- It ensures that the response is coordinated and resources are allocated effectively. (Correct answer)
- It is only needed after the incident is resolved.
Correct answer: It ensures that the response is coordinated and resources are allocated effectively.
Stakeholder involvement in incident response is crucial because it ensures that the response is coordinated, comprehensive, and that resources are allocated effectively. Engaging key stakeholders, including legal, public relations, human resources, and senior management, ensures that all aspects of the incident are addressed. This collaborative approach leads to better decision-making and a more successful resolution.
Question 13: What is the PRIMARY purpose of obtaining CCISO certification in EC-Council Certified CISO?
- To guarantee employment in the field
- To satisfy a personal achievement goal
- To bypass educational requirements
- To demonstrate verified competency and adherence to professional standards (Correct answer)
Correct answer: To demonstrate verified competency and adherence to professional standards
Professional certification demonstrates that an individual has met established competency standards through verified assessment. It provides assurance to employers, clients, and the public that the certified professional possesses the knowledge and skills required for competent practice.
Question 14: What is the recommended approach when managing conflicting priorities in CCISO?
- Delegate all decisions upward
- Address them in alphabetical order
- Ignore lower-priority items
- Prioritize based on impact and urgency (Correct answer)
Correct answer: Prioritize based on impact and urgency
Prioritizing based on impact and urgency ensures the most critical issues receive attention first while maintaining progress on other goals.
Question 15: Privileged Access Management (PAM) solutions are primarily deployed to:
- Provide antivirus protection for servers
- Manage and monitor the use of accounts with elevated administrative rights across enterprise systems (Correct answer)
- Encrypt communications between end-user workstations
- Automate patch management for operating systems
Correct answer: Manage and monitor the use of accounts with elevated administrative rights across enterprise systems
PAM controls, monitors, and audits privileged account usage to reduce the risk of insider misuse or external attackers leveraging compromised administrator credentials.
Question 16: A gap analysis in security strategic planning compares which two states?
- Compliance status vs. regulatory requirements
- Budgeted spend vs. actual spend
- Attacker capabilities vs. defender capabilities
- Current security posture vs. desired future-state security posture (Correct answer)
Correct answer: Current security posture vs. desired future-state security posture
A gap analysis identifies the delta between where the organization is today and where it needs to be to meet strategic security objectives.
Question 17: A CISO discovers that a cloud provider is subcontracting data processing to a fourth-party vendor without notification. This PRIMARILY violates which principle?
- Least privilege
- Due diligence in vendor chain management (Correct answer)
- Data minimization
- Defense in depth
Correct answer: Due diligence in vendor chain management
Undisclosed subcontracting represents a failure of supply chain due diligence, which requires visibility and control over all parties handling organizational data.
Question 18: Why is business continuity planning important for information security?
- It monitors financial performance.
- It ensures employees have adequate vacation time.
- It focuses on improving marketing outreach.
- It ensures that essential operations continue during disruptions. (Correct answer)
Correct answer: It ensures that essential operations continue during disruptions.
Business continuity planning (BCP) is vital for information security because it prepares an organization to maintain critical functions during and after disruptive events, such as cyberattacks, natural disasters, or system failures. By having a BCP, organizations can minimize downtime, ensure the availability of essential systems and data, and recover operations swiftly. This directly supports the availability aspect of information security.
Question 19: During BCP development, which analysis identifies the minimum resources required to resume critical business functions?
- Vulnerability Assessment
- Gap Analysis
- Business Impact Analysis (BIA) (Correct answer)
- Threat and Risk Assessment (TRA)
Correct answer: Business Impact Analysis (BIA)
A BIA identifies critical business functions, their dependencies, and the minimum resources necessary to resume operations within acceptable timeframes.
Question 20: A CISO is evaluating whether to build an internal SOC or outsource to an MSSP. Which financial analysis technique is most appropriate for comparing these two multi-year options?
- Break-even analysis
- Net Present Value (NPV) analysis (Correct answer)
- Payback period calculation
- Gross margin comparison
Correct answer: Net Present Value (NPV) analysis
NPV analysis accounts for the time value of money across multi-year cost streams, making it ideal for comparing build-vs-buy decisions with different upfront and recurring costs.
Question 21: In EC-Council Certified CISO, what is the PRIMARY purpose of conducting regular safety drills and exercises?
- To satisfy insurance requirements only
- To evaluate employee performance reviews
- To reduce daily workload
- To ensure personnel can respond effectively in emergencies (Correct answer)
Correct answer: To ensure personnel can respond effectively in emergencies
Regular safety drills ensure that all personnel are prepared to respond effectively during actual emergencies. Practice builds muscle memory, identifies gaps in emergency procedures, and improves overall response times.
Question 22: What is the MOST important reason for EC-Council Certified CISO professionals to maintain continuing education?
- To accumulate credentials for personal prestige
- To stay current with evolving standards, practices, and regulations (Correct answer)
- To increase billing rates
- To satisfy employer preferences
Correct answer: To stay current with evolving standards, practices, and regulations
Continuing education ensures professionals remain current with evolving industry standards, best practices, and regulatory requirements. This directly impacts the quality of service provided and maintains public trust in the profession.
Question 23: In the context of intellectual property law, which type of protection applies to software source code and documentation by default upon creation?
- Trade secret
- Patent
- Trademark
- Copyright (Correct answer)
Correct answer: Copyright
Copyright protection attaches automatically to original works including software source code the moment they are created and fixed in a tangible medium.
Question 24: Which financial document provides the CISO with the best view of committed but not yet spent security funds across the fiscal year?
- Income statement
- Balance sheet
- Cash flow statement
- Budget vs. actuals report with encumbrances (Correct answer)
Correct answer: Budget vs. actuals report with encumbrances
A budget vs. actuals report that includes encumbrances (committed but unspent funds) shows true available budget by accounting for purchase orders and contracts already in progress.
Question 25: In CCISO practice, what is the primary purpose of strategic planning?
- To satisfy external auditors
- To align resources with goals and anticipate challenges (Correct answer)
- To create paperwork
- To reduce workforce
Correct answer: To align resources with goals and anticipate challenges
Strategic planning aligns organizational resources with goals and helps anticipate challenges before they become critical issues.
Question 26: A CISO adopts an 'assume breach' philosophy in strategic planning. This approach PRIMARILY affects which planning element?
- Perimeter defense investment levels
- Physical security posture
- Employee background check frequency
- Detection, response, and recovery capability investments (Correct answer)
Correct answer: Detection, response, and recovery capability investments
Assume breach shifts strategic focus from prevention-only to robust detection, response, and recovery, accepting that perimeter breaches will occur.
Question 27: Under the NIST Cybersecurity Framework (CSF), which function focuses on developing and implementing appropriate activities to identify cybersecurity risks?
- Detect
- Identify (Correct answer)
- Protect
- Respond
Correct answer: Identify
The Identify function of the NIST CSF develops organizational understanding of managing cybersecurity risk to systems, assets, data, and capabilities.
Question 28: What is the primary purpose of a security program charter in strategic planning?
- To formally establish scope, authority, accountability, and objectives of the security program (Correct answer)
- To serve as the annual security audit report
- To document network diagrams and asset inventories
- To list all approved security vendors
Correct answer: To formally establish scope, authority, accountability, and objectives of the security program
A security program charter defines mandate, scope, roles, authorities, and goals, providing the foundational governance document for the program.
Question 29: What role does collaboration play in business continuity for CCISO professionals?
- It is only needed in emergencies
- It slows down work unnecessarily
- It enhances outcomes through diverse perspectives and shared expertise (Correct answer)
- It reduces individual accountability
Correct answer: It enhances outcomes through diverse perspectives and shared expertise
Collaboration leverages diverse perspectives and combined expertise to achieve better outcomes than any individual could alone.
Question 30: A CISO is tasked with establishing security metrics for the board. Which metric BEST demonstrates the business value of the security program?
- Count of security awareness training completions
- Total number of security policies in place
- Reduction in mean time to detect (MTTD) and respond (MTTR) to incidents (Correct answer)
- Number of vulnerabilities patched per quarter
Correct answer: Reduction in mean time to detect (MTTD) and respond (MTTR) to incidents
MTTD and MTTR directly tie security operational efficiency to business risk reduction, making them meaningful to board-level stakeholders.
Question 31: What does compliance refer to in risk management?
- Following industry best practices for software development.
- Adhering to laws, regulations, and standards that govern the security of information and assets. (Correct answer)
- Minimizing operational costs.
- Increasing system speed.
Correct answer: Adhering to laws, regulations, and standards that govern the security of information and assets.
In risk management, compliance refers to an organization's adherence to relevant laws, regulations, industry standards, and internal policies concerning information security and asset protection. It ensures that the organization operates legally and ethically, avoiding penalties, legal issues, and reputational damage. Compliance is a critical component of a robust risk management strategy.
Question 32: What is the purpose of conducting a gap analysis in governance and risk management?
- To assess financial performance.
- To identify discrepancies and opportunities for improvement in risk management practices. (Correct answer)
- To track employee performance.
- To increase market share.
Correct answer: To identify discrepancies and opportunities for improvement in risk management practices.
The purpose of conducting a gap analysis in governance and risk management is to identify discrepancies between an organization's current practices and its desired state or industry best practices. This analysis highlights areas where improvements are needed to strengthen risk management processes, enhance compliance, and optimize governance structures. It provides a roadmap for targeted enhancements and strategic development.
Question 33: Which approach ensures that security strategic planning remains relevant as the threat landscape evolves?
- Locking the strategy document and revisiting only every 5 years
- Embedding continuous threat intelligence review cycles into strategic planning (Correct answer)
- Relying solely on compliance mandates to trigger strategy updates
- Outsourcing all strategic updates to a consulting firm
Correct answer: Embedding continuous threat intelligence review cycles into strategic planning
Incorporating ongoing threat intelligence into planning cycles ensures the strategy adapts to emerging risks without waiting for a full planning refresh.
Question 34: When developing a risk treatment plan, which element is ESSENTIAL to include to ensure accountability and track progress?
- Named ownership, target completion dates, and success criteria for each action (Correct answer)
- A detailed technical architecture diagram for each control
- Approval signatures from all department heads in the organization
- A full cost-benefit analysis for every possible control alternative
Correct answer: Named ownership, target completion dates, and success criteria for each action
A risk treatment plan must assign clear ownership, deadlines, and measurable success criteria so that progress can be tracked and accountability maintained.
Question 35: When prioritizing recovery efforts, a CISO should base decisions primarily on:
- The age of the technology involved
- The preferences of individual department heads
- System replacement cost
- The criticality and interdependencies identified in the BIA (Correct answer)
Correct answer: The criticality and interdependencies identified in the BIA
The BIA provides objective data on financial and operational impact, enabling the CISO to prioritize recovery of the most critical and interdependent systems first.
Question 36: In the context of CCISO strategic planning, 'strategic risk' is BEST defined as:
- Risks arising from day-to-day IT operations
- Risks documented in the vulnerability scanner
- Regulatory fines for non-compliance
- Risks that could prevent the organization from achieving its long-term business objectives (Correct answer)
Correct answer: Risks that could prevent the organization from achieving its long-term business objectives
Strategic risk refers to high-level uncertainties that threaten the organization's ability to execute its long-term strategy.
Question 37: A CISO is asked to reduce the security budget by 20% mid-year. What is the most appropriate first step?
- Defer all vendor renewals regardless of criticality
- Immediately cut headcount to achieve the target reduction
- Notify regulators of the budget reduction
- Perform a risk impact assessment to identify which cuts introduce the least additional risk (Correct answer)
Correct answer: Perform a risk impact assessment to identify which cuts introduce the least additional risk
Before making cuts, a risk impact assessment identifies which expenditures are critical to risk posture versus optional, enabling informed decisions that minimize exposure.
Question 38: In a hybrid cloud architecture, what is the MOST important architectural consideration for maintaining consistent security policies?
- Using separate security teams for cloud and on-premises
- Using identical hardware from the same vendor
- Hosting all sensitive data on-premises only
- Implementing a unified identity and access management (IAM) framework across on-premises and cloud environments (Correct answer)
Correct answer: Implementing a unified identity and access management (IAM) framework across on-premises and cloud environments
A unified IAM framework ensures consistent identity verification, access controls, and policy enforcement across hybrid environments, preventing security gaps at integration points.
Question 39: Which statement BEST describes the relationship between EC-Council Certified CISO certification requirements and industry evolution?
- Requirements become less stringent over time
- Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards (Correct answer)
- Changes only occur when government mandates new requirements
- Certification requirements never change once established
Correct answer: Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards
Certification requirements evolve to keep pace with advances in professional knowledge, technological developments, and changes in practice standards. This ensures that certified professionals remain current and competent in a changing professional landscape.
Question 40: Which of the following is an example of a preventive BC control rather than a recovery BC control?
- Activating the crisis communication plan
- Failover to a hot site after a primary data center fire
- Restoring data from off-site backup tapes
- Installing uninterruptible power supplies (UPS) to prevent power outages (Correct answer)
Correct answer: Installing uninterruptible power supplies (UPS) to prevent power outages
A UPS is a preventive control that avoids downtime by maintaining power during outages, preventing a disruption from occurring in the first place.
Question 41: What is the most effective approach to strategic planning in the CCISO field?
- Systematic planning and continuous improvement (Correct answer)
- Maintaining the status quo
- Reactive problem-solving
- Following competitors
Correct answer: Systematic planning and continuous improvement
Systematic planning combined with continuous improvement ensures sustainable success and allows for proactive management of challenges.
Question 42: Why is vulnerability management important in a security program?
- It helps identify and address system weaknesses before they are exploited. (Correct answer)
- It tracks customer satisfaction.
- It increases the company’s revenue.
- It focuses on tracking employee performance.
Correct answer: It helps identify and address system weaknesses before they are exploited.
Vulnerability management is crucial in a security program as it involves the continuous process of identifying, assessing, prioritizing, and remediating security weaknesses in systems and applications. By proactively addressing these vulnerabilities, organizations can close potential entry points for attackers before they can be exploited. This systematic approach significantly strengthens the overall security posture and reduces the likelihood of successful cyberattacks.
Question 43: In CCISO practice, what is the primary purpose of strategic planning?
- To create paperwork
- To align resources with goals and anticipate challenges (Correct answer)
- To satisfy external auditors
- To reduce workforce
Correct answer: To align resources with goals and anticipate challenges
Strategic planning aligns organizational resources with goals and helps anticipate challenges before they become critical issues.
Question 44: When prioritizing strategic security initiatives, a CISO should PRIMARILY consider:
- Vendor recommendations and product roadmaps
- Industry peers' technology choices
- Regulatory penalties alone
- Risk reduction value relative to business impact and available resources (Correct answer)
Correct answer: Risk reduction value relative to business impact and available resources
Initiative prioritization must weigh risk reduction potential against business impact and resource constraints for maximum strategic value.
Question 45: During post-incident analysis, the IR team determines that the mean time to detect (MTTD) was 47 days. As CISO, which metric should you prioritize improving first to reduce business impact from future incidents?
- Mean time to contain (MTTC)
- Mean time to detect (MTTD) (Correct answer)
- Mean time to recover (MTTR)
- Mean time between failures (MTBF)
Correct answer: Mean time to detect (MTTD)
Reducing MTTD shortens the window attackers have to cause damage, directly reducing overall business impact before containment can even begin.
Question 46: Which risk management approach is MOST effective for CCISO professionals when evaluating potential workplace hazards?
- Proactive hazard identification and assessment (Correct answer)
- Relying solely on historical accident data
- Delegating all safety decisions to management
- Reactive analysis after incidents occur
Correct answer: Proactive hazard identification and assessment
Proactive hazard identification and assessment allows professionals to identify and mitigate risks before incidents occur, which is far more effective than reactive approaches that only address problems after they happen.
Question 47: A CISO must develop a Business Continuity Plan (BCP). Which metric defines the maximum acceptable amount of time a system can be offline before causing unacceptable business impact?
- Recovery Point Objective (RPO)
- Maximum Tolerable Downtime (MTD)
- Recovery Time Objective (RTO) (Correct answer)
- Mean Time Between Failures (MTBF)
Correct answer: Recovery Time Objective (RTO)
RTO specifies the target time within which a system must be restored after a disruption to avoid unacceptable consequences.
Question 48: A CISO is tasked with aligning the security roadmap to a 3-year business transformation. Which planning horizon best describes this effort?
- Operational planning
- Strategic planning (Correct answer)
- Contingency planning
- Tactical planning
Correct answer: Strategic planning
Strategic planning addresses long-term goals (typically 3–5 years) and aligns security initiatives with overall business direction.
Question 49: Which risk treatment option is applied when an organization decides to stop performing an activity that generates unacceptable risk?
- Risk avoidance (Correct answer)
- Risk mitigation
- Risk acceptance
- Risk transfer
Correct answer: Risk avoidance
Risk avoidance eliminates the risk by discontinuing the activity or process that creates the unacceptable exposure.
Question 50: What is the role of governance in the context of risk management?
- To establish a structured approach for managing risks and ensuring compliance. (Correct answer)
- To monitor employee performance.
- To reduce operational costs.
- To increase organizational revenue.
Correct answer: To establish a structured approach for managing risks and ensuring compliance.
Governance in risk management establishes the overarching framework, policies, and processes that guide an organization's approach to identifying, assessing, and mitigating risks. It ensures that risk management activities are aligned with strategic objectives and that responsibilities are clearly defined. This structured approach helps ensure compliance with internal policies and external regulations.
Question 51: Which security architecture model uses the concept of 'never trust, always verify' as its foundational principle?
- Zero Trust Architecture (Correct answer)
- Jericho Forum Model
- Defense-in-Depth
- Perimeter Security Model
Correct answer: Zero Trust Architecture
Zero Trust Architecture (ZTA) operates on the principle that no user, device, or network segment is inherently trusted, requiring continuous verification of every access request.
Question 52: When conducting a SWOT analysis for information security strategy, which quadrant specifically examines internal deficiencies that could hinder security objectives?
- Strengths
- Weaknesses (Correct answer)
- Threats
- Opportunities
Correct answer: Weaknesses
Weaknesses represent internal deficiencies such as skill gaps, legacy systems, or budget constraints that can undermine security goals.
Question 53: A CISO is preparing a 5-year security strategy immediately following a major data breach. Which element should receive HIGHEST priority in the early phases?
- Renegotiating all vendor contracts
- Long-term technology procurement planning
- Restructuring the entire security organization
- Immediate capability gaps in detection and response exposed by the breach (Correct answer)
Correct answer: Immediate capability gaps in detection and response exposed by the breach
Post-breach strategic planning must first address the specific capability failures exposed by the incident before focusing on longer-term transformation.
Question 54: What is the importance of monitoring security logs in risk management?
- To track financial expenditures.
- To reduce operational costs.
- To detect and respond to potential security threats quickly. (Correct answer)
- To improve employee performance.
Correct answer: To detect and respond to potential security threats quickly.
Monitoring security logs is essential for risk management as logs record system activities, user actions, and network events. Analyzing these logs allows security teams to detect anomalous behavior, identify potential security breaches, and respond to threats in real time. This proactive detection and rapid response capability significantly reduces the window of opportunity for attackers and mitigates potential damage.
Question 55: What is the primary objective of an Identity and Access Management (IAM) program within an enterprise?
- Monitoring network traffic for intrusions
- Encrypting all data at rest and in transit
- Ensuring the right individuals access the right resources at the right times for the right reasons (Correct answer)
- Managing software licensing and asset inventory
Correct answer: Ensuring the right individuals access the right resources at the right times for the right reasons
IAM programs are designed to ensure appropriate access by verified identities to authorized resources, balancing security with operational efficiency.
Question 56: During a vendor risk assessment, the security team discovers a critical supplier uses the same IT infrastructure for multiple clients with no logical separation. This BEST represents which type of risk?
- Operational risk
- Reputational risk
- Concentration risk (Correct answer)
- Regulatory risk
Correct answer: Concentration risk
Concentration risk arises when a vendor's shared infrastructure creates potential exposure where a breach affecting one client could impact others.
Question 57: A CISO presents a security strategy to the board but receives pushback that it conflicts with a planned acquisition. This scenario highlights the importance of:
- Integrating security strategy into enterprise strategic planning cycles (Correct answer)
- Annual penetration testing
- Increasing the security budget
- Stricter access control policies
Correct answer: Integrating security strategy into enterprise strategic planning cycles
Security strategy must be synchronized with enterprise planning cycles so that major business events like acquisitions are considered from the outset.
Question 58: Which security architecture principle states that a subject should only have the minimum access rights necessary to perform its authorized functions?
- Job rotation
- Need-to-know
- Least privilege (Correct answer)
- Separation of duties
Correct answer: Least privilege
The principle of least privilege limits user and system permissions to the minimum required to accomplish legitimate tasks, reducing the potential damage from errors, attacks, or compromised accounts.
Question 59: A CISO uses Porter's Five Forces model during strategic planning. Which force directly relates to the risk posed by disruptive technology replacing existing security solutions?
- Threat of new entrants
- Bargaining power of suppliers
- Rivalry among existing competitors
- Threat of substitute products (Correct answer)
Correct answer: Threat of substitute products
The threat of substitutes captures the risk that alternative technologies or approaches could render current security tools obsolete.
Question 60: Data classification programs are PRIMARILY intended to:
- Define the technical architecture for data storage systems
- Identify personnel authorized to access classified government information
- Ensure that information is protected at a level commensurate with its value and sensitivity (Correct answer)
- Comply with international data transfer regulations automatically
Correct answer: Ensure that information is protected at a level commensurate with its value and sensitivity
Data classification establishes categories of sensitivity so that appropriate security controls can be applied proportionally to protect data based on its business value and risk.
Question 61: A CISO wants to quantify the financial return of security controls to justify budget increases. The MOST appropriate method is:
- Return on Security Investment (ROSI) analysis using risk reduction and loss expectancy (Correct answer)
- Headcount ratio of security staff to total employees
- CVSS scoring of identified vulnerabilities
- Number of security incidents closed per quarter
Correct answer: Return on Security Investment (ROSI) analysis using risk reduction and loss expectancy
ROSI calculates expected loss reduction against control cost, providing a financial justification framework for security investment decisions.
Question 62: An attacker used compromised credentials obtained via credential stuffing to access a customer portal. After containment, which remediation action has the highest long-term impact on preventing recurrence?
- Resetting only the compromised accounts
- Blocking the attacker's IP addresses permanently
- Increasing password minimum length to 10 characters
- Implementing multi-factor authentication across all customer-facing portals (Correct answer)
Correct answer: Implementing multi-factor authentication across all customer-facing portals
MFA prevents credential stuffing attacks from succeeding even when valid credentials are obtained, addressing the root cause rather than symptoms.
Question 63: In EC-Council Certified CISO practice, what is the FIRST step when a safety hazard is identified in the workplace?
- Wait for a supervisor to notice the issue
- Continue working and report at end of shift
- Immediately secure the area and report the hazard (Correct answer)
- Document it for the next safety audit
Correct answer: Immediately secure the area and report the hazard
When a safety hazard is identified, the immediate priority is to secure the area to prevent injury and report the hazard through proper channels. Delaying action increases the risk of incidents.
Question 64: The principle of separation of duties (SoD) in IAM is primarily designed to prevent:
- Network-level eavesdropping on authentication traffic
- Weak password usage by employees
- Fraud and errors by requiring more than one person to complete a sensitive task or transaction (Correct answer)
- Unauthorized physical access to data centers
Correct answer: Fraud and errors by requiring more than one person to complete a sensitive task or transaction
Separation of duties ensures no single individual has enough access to complete a sensitive action alone, requiring collusion between multiple parties to commit fraud or cause significant errors.
Question 65: Which personal protective equipment (PPE) principle applies to ALL CCISO certified professionals regardless of their specific role?
- PPE is only necessary during formal inspections
- Any PPE will provide adequate protection
- PPE must be properly fitted, maintained, and replaced as needed (Correct answer)
- PPE is optional if experienced in the field
Correct answer: PPE must be properly fitted, maintained, and replaced as needed
Regardless of experience level or specific role, PPE must be properly fitted to the individual, regularly maintained in good condition, and replaced when worn or damaged. Improperly fitted or degraded PPE can provide a false sense of security.
Question 66: In CCISO practice, what is the purpose of vulnerability scanning?
- To slow down network traffic
- To identify weaknesses before attackers do (Correct answer)
- To replace firewalls
- To exploit systems
Correct answer: To identify weaknesses before attackers do
Vulnerability scanning proactively identifies security weaknesses in systems and applications so they can be remediated before exploitation.
Question 67: A CISO discovers that a third-party vendor with access to sensitive customer data has not undergone a security assessment. Which risk management step should have prevented this gap?
- Risk communication
- Risk identification (Correct answer)
- Risk monitoring
- Risk treatment
Correct answer: Risk identification
Risk identification should encompass all assets and relationships including third-party vendors; failure to identify this risk source means it was excluded from the assessment scope.
Question 68: Why is an incident response plan essential in a security program?
- It provides a structured approach to managing and recovering from security incidents. (Correct answer)
- It helps track financial transactions.
- It focuses on increasing system speed.
- It helps monitor employee attendance.
Correct answer: It provides a structured approach to managing and recovering from security incidents.
An incident response plan is essential in a security program because it provides a predefined, structured approach for an organization to effectively manage and recover from security incidents. This plan outlines the steps to detect, analyze, contain, eradicate, and recover from breaches, minimizing damage and downtime. A well-executed plan ensures business continuity and helps maintain trust and compliance.
Question 69: Why is risk assessment essential for an organization?
- To reduce the time spent on IT tasks.
- To understand the impact of potential risks and prioritize actions. (Correct answer)
- To meet regulatory requirements.
- To improve financial reporting.
Correct answer: To understand the impact of potential risks and prioritize actions.
Risk assessment is essential for an organization because it provides a clear understanding of the potential impact of various risks and allows for their prioritization. By evaluating the likelihood and consequence of each identified risk, organizations can allocate resources effectively to mitigate the most critical threats. This process enables informed decision-making and strategic planning to protect assets and operations.
Question 70: Which metric is most useful for evaluating program effectiveness in CCISO?
- Amount of money spent
- Number of meetings held
- Number of staff involved
- Outcome-based performance indicators (Correct answer)
Correct answer: Outcome-based performance indicators
Outcome-based performance indicators directly measure whether the program is achieving its intended results and goals.
Question 71: A fourth-party risk scenario occurs when:
- An organization directly suffers a cyberattack
- A regulatory body audits the organization's vendor list
- A vendor fails to meet SLA targets
- A vendor's own subcontractor causes a breach affecting your organization (Correct answer)
Correct answer: A vendor's own subcontractor causes a breach affecting your organization
Fourth-party risk occurs when a vendor's supplier or subcontractor (a party not directly contracted by you) causes a security incident affecting your organization.
Question 72: What is the recommended first step when a CCISO professional identifies a compliance violation?
- Discuss on social media
- Ignore it if minor
- Wait for someone else to report it
- Document and report through proper channels (Correct answer)
Correct answer: Document and report through proper channels
All compliance violations should be documented and reported through established channels to ensure proper investigation and resolution.
Question 73: A CISO is presenting the security program's financial performance to the audit committee. Which metric demonstrates that security spending is generating measurable risk reduction over time?
- Percentage of IT budget allocated to security
- Trend of declining ALE combined with stable or decreasing security spend per protected asset (Correct answer)
- Number of security tools deployed across the organization
- Total security headcount growth year-over-year
Correct answer: Trend of declining ALE combined with stable or decreasing security spend per protected asset
Declining ALE alongside stable or reduced per-asset spending demonstrates efficiency — the program is reducing financial risk exposure without proportional cost increases.
Question 74: What is the difference between a risk and a threat in information security?
- A risk is the potential, while a threat is the source of harm. (Correct answer)
- A risk is a type of threat.
- There is no difference.
- A threat is a preventive measure.
Correct answer: A risk is the potential, while a threat is the source of harm.
In information security, a threat is a potential cause of an unwanted incident that may result in harm to a system or organization, such as a malicious actor or a natural disaster. A risk, on the other hand, is the potential for loss or damage resulting from a threat exploiting a vulnerability. Understanding this distinction is crucial for effective risk assessment and mitigation strategies.
Question 75: A CISO is evaluating the maturity of the security program using CMMI. The organization consistently follows defined, documented processes but does not yet measure process effectiveness. Which maturity level does this represent?
- Level 1 – Initial
- Level 2 – Managed
- Level 4 – Quantitatively Managed
- Level 3 – Defined (Correct answer)
Correct answer: Level 3 – Defined
CMMI Level 3 (Defined) means processes are standardized and documented organization-wide, but measurement and control come at Level 4.
Question 76: A CISO is evaluating third-party vendors for cloud storage services. Which contractual clause BEST ensures the organization retains ownership of its data if the vendor relationship ends?
- Indemnification clause
- Service Level Agreement (SLA)
- Data portability and return clause (Correct answer)
- Non-disclosure agreement (NDA)
Correct answer: Data portability and return clause
A data portability and return clause contractually obligates the vendor to return or delete organizational data upon contract termination, ensuring data sovereignty.
Question 77: What is the role of access control in a security program?
- It helps to monitor employee attendance.
- It increases system speed.
- It tracks financial transactions.
- It ensures that only authorized individuals can access sensitive systems and data. (Correct answer)
Correct answer: It ensures that only authorized individuals can access sensitive systems and data.
Access control is a fundamental security measure in any security program, designed to regulate who or what can view or use resources in a computing environment. It ensures that only authorized individuals, processes, or systems are granted access to sensitive data and systems. By enforcing strict access policies, organizations can prevent unauthorized access, reduce the risk of data breaches, and maintain data confidentiality and integrity.
Question 78: Which of the following is an example of a leading indicator for measuring security program effectiveness?
- Number of regulatory fines received
- Number of data breaches in the past year
- Total cost of incidents in the previous fiscal year
- Percentage of employees who completed security awareness training this quarter (Correct answer)
Correct answer: Percentage of employees who completed security awareness training this quarter
Leading indicators measure proactive activities (like training completion) that predict future security posture, as opposed to lagging indicators that measure past failures.
Question 79: In strategic planning, 'capability maturity' assessments help a CISO to:
- Benchmark current security practices against a defined scale to prioritize improvements (Correct answer)
- Certify staff competency levels
- Satisfy annual audit requirements
- Identify specific exploited vulnerabilities
Correct answer: Benchmark current security practices against a defined scale to prioritize improvements
Capability maturity models (e.g., CMM, C2M2) measure process maturity on a defined scale and guide investment in areas needing improvement.
Question 80: A CISO is preparing an audit report for the board. Which characteristic is most important for the executive summary?
- Concise risk-ranked findings with business impact and remediation priorities (Correct answer)
- Detailed statistical analysis of sample populations
- Inclusion of all technical details and raw data
- A comprehensive list of all audit procedures performed
Correct answer: Concise risk-ranked findings with business impact and remediation priorities
Executive summaries should present risk-ranked findings with clear business impact and prioritized recommendations to support board-level decision-making.
Question 81: Which metric is most useful for evaluating program effectiveness in CCISO?
- Amount of money spent
- Number of staff involved
- Outcome-based performance indicators (Correct answer)
- Number of meetings held
Correct answer: Outcome-based performance indicators
Outcome-based performance indicators directly measure whether the program is achieving its intended results and goals.
Question 82: What security architectural pattern does a Content Delivery Network (CDN) with DDoS mitigation capability primarily implement?
- Data loss prevention at the edge
- Zero-knowledge encryption of cached content
- Multi-factor authentication for content access
- Distributed traffic absorption and scrubbing that protects origin servers by dispersing attack traffic across global points of presence (Correct answer)
Correct answer: Distributed traffic absorption and scrubbing that protects origin servers by dispersing attack traffic across global points of presence
CDNs with DDoS mitigation absorb and filter attack traffic at globally distributed edge nodes, preventing volumetric attacks from overwhelming origin infrastructure.
Question 83: In EC-Council Certified CISO, what is the PRIMARY purpose of conducting regular safety drills and exercises?
- To evaluate employee performance reviews
- To ensure personnel can respond effectively in emergencies (Correct answer)
- To reduce daily workload
- To satisfy insurance requirements only
Correct answer: To ensure personnel can respond effectively in emergencies
Regular safety drills ensure that all personnel are prepared to respond effectively during actual emergencies. Practice builds muscle memory, identifies gaps in emergency procedures, and improves overall response times.
Question 84: When developing a security program charter, which element is MOST critical to include to ensure executive sponsorship?
- Specific vulnerability remediation timelines
- Detailed technical architecture diagrams
- List of all security tools and vendors
- Defined authority, scope, and accountability of the security function (Correct answer)
Correct answer: Defined authority, scope, and accountability of the security function
A charter must define authority and scope so that executives understand and formally delegate responsibility to the CISO.
Question 85: A CISO is selecting between two vendors: one holds ISO 27001 certification and the other provides a SOC 2 Type II report. Which statement BEST describes the difference?
- Both certifications are identical in scope and value
- ISO 27001 certifies an ISMS against a standard; SOC 2 Type II reports on operational effectiveness of controls over a period (Correct answer)
- SOC 2 is a certification; ISO 27001 is an audit report
- ISO 27001 is US-specific; SOC 2 is international
Correct answer: ISO 27001 certifies an ISMS against a standard; SOC 2 Type II reports on operational effectiveness of controls over a period
ISO 27001 is a management system certification, while SOC 2 Type II is an attestation report covering the operational effectiveness of controls over a defined review period.
Question 86: When integrating cybersecurity into enterprise risk management (ERM), the CISO's role is to:
- Manage only technical risks within the IT department
- Translate cyber risks into business-impact terms understood by risk and finance executives (Correct answer)
- Replace the Chief Risk Officer's responsibilities
- Eliminate all residual cyber risk
Correct answer: Translate cyber risks into business-impact terms understood by risk and finance executives
The CISO bridges the gap between technical cyber risk and business risk language so that cyber risks are properly reflected in the ERM framework.
Question 87: A CISO's strategic plan includes a zero-trust network architecture initiative. Which business driver MOST likely justified this investment?
- Regulatory mandate requiring zero-trust specifically
- Budget surplus at the end of the fiscal year
- Increasing remote work and cloud adoption that eroded traditional perimeter controls (Correct answer)
- Desire to reduce the number of security vendors
Correct answer: Increasing remote work and cloud adoption that eroded traditional perimeter controls
Zero-trust architectures are primarily driven by the dissolution of network perimeters due to remote work, cloud services, and mobile devices.
Question 88: Which document typically serves as the top-level policy artifact that gives the CISO authority to enforce the security strategy?
- Business continuity plan
- Network security standard
- Incident response plan
- Information security charter (Correct answer)
Correct answer: Information security charter
An information security charter (or policy) establishes executive-level mandate for security governance and the CISO's authority.
Question 89: A CISO reviews the incident response team's post-incident report and notices that root cause analysis was skipped to meet reporting deadlines. What risk does this create?
- Failure to identify systemic vulnerabilities, increasing the likelihood of repeat incidents (Correct answer)
- Automatic audit finding requiring a fine
- Regulatory requirement to re-open the incident
- Increased legal liability for documenting the attack
Correct answer: Failure to identify systemic vulnerabilities, increasing the likelihood of repeat incidents
Skipping root cause analysis leaves underlying vulnerabilities unaddressed, making the organization susceptible to identical or similar attacks in the future.
Question 90: When a CISO develops security strategy for an organization operating in a heavily regulated industry, regulatory compliance requirements should be treated as:
- Optional guidelines subject to cost-benefit analysis
- The sole driver of the security strategy
- A baseline constraint, with risk-driven priorities built above that floor (Correct answer)
- Responsibility of the legal department, not the CISO
Correct answer: A baseline constraint, with risk-driven priorities built above that floor
Compliance sets a minimum required baseline; effective security strategy layers risk-driven controls above that floor to address actual threats.
Question 91: During strategic planning, a CISO identifies that a proposed cloud migration increases residual risk beyond the board's appetite. The BEST response is to:
- Accept the risk without disclosure
- Transfer all risk to the cloud provider
- Halt the migration indefinitely
- Escalate findings and propose risk treatment options to leadership (Correct answer)
Correct answer: Escalate findings and propose risk treatment options to leadership
The CISO should surface findings to decision-makers and present treatment options so leadership can make informed risk-acceptance decisions.
Question 92: Which US federal law established the framework for protecting critical infrastructure information shared between the private sector and the government?
- E-Government Act
- FISMA
- PATRIOT Act
- CISA 2015 (Correct answer)
Correct answer: CISA 2015
The Cybersecurity Information Sharing Act (CISA) of 2015 established protections and procedures for sharing cyber threat indicators between private entities and the federal government.
Question 93: Which framework is most commonly used to cascade high-level security strategy into measurable departmental objectives?
- Balanced Scorecard (Correct answer)
- NIST RMF
- ISO 27001 Annex A
- COBIT 2019
Correct answer: Balanced Scorecard
The Balanced Scorecard translates strategic vision into four perspectives—financial, customer, internal process, and learning—with linked KPIs.
Question 94: Which skill is most critical for effective financial management?
- Communication and stakeholder engagement (Correct answer)
- Individual work preferences
- Speed of decision-making
- Technical expertise alone
Correct answer: Communication and stakeholder engagement
Communication and stakeholder engagement are essential because management success depends on effectively coordinating with and influencing others.
Question 95: An audit reveals that compensating controls exist where a primary control has failed. How should the CISO treat residual risk in this scenario?
- Evaluate whether the compensating controls sufficiently reduce residual risk to an acceptable level (Correct answer)
- Require full remediation of the primary control regardless of compensating controls
- Immediately escalate to the board as a critical finding
- Accept residual risk without further action because compensating controls exist
Correct answer: Evaluate whether the compensating controls sufficiently reduce residual risk to an acceptable level
Compensating controls must be evaluated to confirm they adequately reduce residual risk before accepting the current state.
Question 96: Which approach BEST describes integrating security into an organization's SDLC?
- Performing penetration testing only before production releases
- Installing WAFs in front of all applications
- Requiring developers to pass a security certification
- Embedding security requirements, reviews, and testing at every phase of development (Correct answer)
Correct answer: Embedding security requirements, reviews, and testing at every phase of development
A DevSecOps approach embeds security throughout all SDLC phases rather than treating it as a gate at the end.
Question 97: What is the MOST effective way for new CCISO professionals to build competency in their field?
- Focusing solely on the most advanced topics
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
- Learning entirely through trial and error
- Studying certification materials exclusively
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building professional competency requires a multi-faceted approach: formal education provides foundational knowledge, mentored practice develops applied skills under guidance, and ongoing professional development ensures continuous growth and currency in the field.
Question 98: A CISO wants to reduce the impact of a critical vendor going bankrupt. Which strategy is MOST effective for ensuring business continuity?
- Negotiate lower contract pricing
- Develop an alternative vendor or escrow arrangement (Correct answer)
- Increase the frequency of invoice reviews
- Require the vendor to purchase insurance
Correct answer: Develop an alternative vendor or escrow arrangement
Maintaining an alternative vendor or software escrow arrangement ensures continuity of critical services if the primary vendor ceases operations.
Question 99: Which access control model makes access decisions based on data classification labels and user security clearances assigned by a central authority?
- Role-Based Access Control (RBAC)
- Discretionary Access Control (DAC)
- Attribute-Based Access Control (ABAC)
- Mandatory Access Control (MAC) (Correct answer)
Correct answer: Mandatory Access Control (MAC)
MAC uses centrally controlled sensitivity labels on objects and clearance levels on subjects, with access determined by policy rather than owner discretion—commonly used in government environments.
Question 100: An organization's BCP requires restoring operations within 4 hours but the BIA identified an MTD of 6 hours. Which statement is correct?
- The MTD must always equal the RTO to be compliant
- The RTO exceeds the MTD, creating an unacceptable risk gap
- The RTO is within the MTD, providing an acceptable recovery buffer (Correct answer)
- The RTO and MTD values are irrelevant to each other
Correct answer: The RTO is within the MTD, providing an acceptable recovery buffer
When the RTO (4 hours) is less than the MTD (6 hours), the organization can restore operations before irreversible harm occurs, which is the desired BC posture.
Question 101: A CISO must decide how long to retain incident-related logs and forensic artifacts. Which factor should MOST influence this retention period?
- IT department preference for data minimization
- Available storage capacity only
- Marketing analytics needs
- Legal hold requirements, regulatory mandates, and statute of limitations for potential litigation (Correct answer)
Correct answer: Legal hold requirements, regulatory mandates, and statute of limitations for potential litigation
Legal holds, regulatory requirements, and litigation timelines dictate minimum retention periods for incident artifacts to ensure evidence availability for legal and compliance purposes.
Question 102: What is the key benefit of evidence-based decision making in CCISO management?
- It speeds up all processes
- It reduces reliance on data
- It improves accuracy and reduces bias in decisions (Correct answer)
- It eliminates all risk
Correct answer: It improves accuracy and reduces bias in decisions
Evidence-based decision making uses data and research to improve the accuracy of decisions and reduce the influence of personal bias.
Question 103: When conducting a risk assessment for CCISO operations, which factor should receive the HIGHEST priority?
- Cost of implementing safety measures
- Time required for safety training
- Probability and severity of potential harm (Correct answer)
- Convenience for daily operations
Correct answer: Probability and severity of potential harm
The probability and severity of potential harm are the primary factors in risk assessment. While cost and convenience are considerations, they should never override the assessment of how likely an incident is and how severe its consequences could be.
Question 104: Which metric BEST measures the effectiveness of a vulnerability management program within a security program?
- Number of vulnerability management staff employed
- Total number of vulnerability scans conducted per month
- Total count of open vulnerabilities in the scanner
- Mean time to remediate (MTTR) critical vulnerabilities within defined SLA targets (Correct answer)
Correct answer: Mean time to remediate (MTTR) critical vulnerabilities within defined SLA targets
MTTR against defined SLAs measures whether the program is actually closing risk in a timely manner, not just discovering vulnerabilities.
Question 105: What is the most effective approach to audit management in the CCISO field?
- Systematic planning and continuous improvement (Correct answer)
- Following competitors
- Reactive problem-solving
- Maintaining the status quo
Correct answer: Systematic planning and continuous improvement
Systematic planning combined with continuous improvement ensures sustainable success and allows for proactive management of challenges.
Question 106: Which of the following is a key reason organizations implement geographic diversity in their BC strategy?
- To comply with data sovereignty laws exclusively
- To avoid single points of failure due to regional disasters (Correct answer)
- To improve application performance for end users
- To reduce software licensing costs
Correct answer: To avoid single points of failure due to regional disasters
Geographic diversity ensures that a regional disaster (earthquake, hurricane, power grid failure) cannot simultaneously affect both the primary and recovery sites.
Question 107: During an audit, the team discovers evidence of potential fraud. What is the CISO's immediate priority?
- Immediately notify appropriate parties (legal, board, audit committee) and preserve evidence (Correct answer)
- Delete audit logs to prevent premature disclosure
- Confront the suspected employee to obtain a confession
- Complete the scheduled audit before reporting the potential fraud
Correct answer: Immediately notify appropriate parties (legal, board, audit committee) and preserve evidence
Suspected fraud must be immediately escalated to legal counsel, the audit committee, and appropriate management while preserving evidence for investigation.
Question 108: Under GDPR, what is the maximum time frame for reporting a personal data breach to the supervisory authority after becoming aware of it?
- 48 hours
- 96 hours
- 24 hours
- 72 hours (Correct answer)
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 109: In CCISO certification, what does redundancy in system design primarily provide?
- Fault tolerance and high availability (Correct answer)
- Increased complexity
- Lower initial cost
- Simplified maintenance
Correct answer: Fault tolerance and high availability
Redundancy provides fault tolerance by ensuring that if one component fails, backup components maintain system availability.
Question 110: A security team implements a honeypot on the network. What is the PRIMARY purpose of this deception technology?
- Providing redundancy for critical systems
- Blocking malicious traffic at the perimeter
- Encrypting sensitive data in transit
- Detecting and studying attacker behavior (Correct answer)
Correct answer: Detecting and studying attacker behavior
Honeypots are decoy systems designed to attract attackers, allowing security teams to study their tactics and gather threat intelligence.
Question 111: A CISO is implementing a security awareness training program. Which metric best measures the program's effectiveness at reducing human risk?
- Number of security policies acknowledged
- Number of training sessions completed
- Total hours of security training delivered
- Reduction in phishing simulation click rates over time (Correct answer)
Correct answer: Reduction in phishing simulation click rates over time
Tracking phishing simulation click rates over time measures actual behavioral change, which is the ultimate goal of security awareness training.
Question 112: A CISO must understand the concept of 'safe harbor' in data privacy law. In the context of GDPR, which mechanism serves as a safe harbor for transferring personal data to the US?
- Standard Contractual Clauses (SCCs) (Correct answer)
- Privacy Shield (currently valid)
- Binding Safe Harbor Agreement
- APEC Cross-Border Privacy Rules
Correct answer: Standard Contractual Clauses (SCCs)
Following the invalidation of Privacy Shield by Schrems II, Standard Contractual Clauses (SCCs) are the primary mechanism for lawful EU-to-US personal data transfers.
Question 113: An organization operating in California must comply with CCPA. Which right does CCPA grant to consumers regarding personal information held by businesses?
- Right to data portability only
- Right to restrict automated processing
- Right to erasure and rectification
- Right to know, delete, and opt-out of sale (Correct answer)
Correct answer: Right to know, delete, and opt-out of sale
CCPA grants California consumers the right to know what personal information is collected, the right to delete it, and the right to opt-out of its sale.
Question 114: Which scenario BEST illustrates misalignment between security strategy and business strategy?
- The security team blocks a merger due to undisclosed cyber risks (Correct answer)
- Security KPIs are reported in quarterly business reviews
- Security budget increases alongside revenue growth
- A CISO hires staff to support a planned cloud migration
Correct answer: The security team blocks a merger due to undisclosed cyber risks
If security risks from a merger are not surfaced until they cause a blockage, the security program is reactive rather than integrated with business strategy.
Question 115: A CCISO certified professional is asked to provide services outside their scope of competence. The CORRECT ethical response is to:
- Decline and refer to a qualified professional (Correct answer)
- Accept and learn as they go
- Accept but charge a lower rate
- Accept the work to gain new experience
Correct answer: Decline and refer to a qualified professional
Ethical practice requires professionals to work within their scope of competence. Accepting work beyond one's qualifications can lead to substandard results and potential harm. Referring to qualified professionals ensures proper service delivery.
Question 116: How do governance, risk management, and compliance (GRC) work together?
- They are used for auditing purposes only.
- They are separate and unrelated processes.
- They integrate into a unified approach for effective organizational risk management. (Correct answer)
- They only focus on financial reporting.
Correct answer: They integrate into a unified approach for effective organizational risk management.
Governance, Risk Management, and Compliance (GRC) work together by integrating these three critical functions into a unified and coherent approach. Governance provides the strategic direction and oversight, risk management identifies and mitigates threats to achieving objectives, and compliance ensures adherence to rules and regulations. This integration ensures that an organization's operations are ethical, secure, and aligned with its goals.
Question 117: In CCISO certification, what is the primary purpose of regulatory compliance programs?
- To increase revenue
- To reduce staffing needs
- To ensure adherence to laws and standards (Correct answer)
- To eliminate competition
Correct answer: To ensure adherence to laws and standards
Regulatory compliance programs are designed to ensure organizations follow applicable laws, regulations, and standards.
Question 118: When evaluating a security architecture against the NIST Cybersecurity Framework (CSF), which core function focuses on implementing appropriate safeguards to ensure delivery of critical infrastructure services?
- Protect (Correct answer)
- Detect
- Respond
- Identify
Correct answer: Protect
The 'Protect' function of the NIST CSF focuses on developing and implementing appropriate safeguards to limit or contain the impact of a potential cybersecurity event.
Question 119: Which personal protective equipment (PPE) principle applies to ALL CCISO certified professionals regardless of their specific role?
- PPE must be properly fitted, maintained, and replaced as needed (Correct answer)
- Any PPE will provide adequate protection
- PPE is only necessary during formal inspections
- PPE is optional if experienced in the field
Correct answer: PPE must be properly fitted, maintained, and replaced as needed
Regardless of experience level or specific role, PPE must be properly fitted to the individual, regularly maintained in good condition, and replaced when worn or damaged. Improperly fitted or degraded PPE can provide a false sense of security.
Question 120: In a Software-Defined Networking (SDN) architecture, what is the primary security concern introduced by centralizing network control in the SDN controller?
- Difficulty implementing VLANs in software-defined environments
- Incompatibility with legacy firewall solutions
- Increased network latency due to central processing
- The SDN controller becomes a high-value single point of attack that, if compromised, allows complete network manipulation (Correct answer)
Correct answer: The SDN controller becomes a high-value single point of attack that, if compromised, allows complete network manipulation
The centralized SDN controller is a critical single point of failure and a high-value target; compromising it gives an attacker full control over network routing, segmentation, and traffic flows.
Question 121: When a CCISO professional faces pressure to compromise professional standards, the BEST response is to:
- Ignore the pressure and continue without reporting
- Comply to maintain workplace relationships
- Immediately resign from the position
- Document the pressure and uphold professional standards (Correct answer)
Correct answer: Document the pressure and uphold professional standards
Professionals should document any pressure to compromise standards and continue upholding their professional obligations. Documentation creates a record of the situation while maintaining ethical integrity.
Question 122: What is the significance of continuous monitoring in security program management?
- It helps to improve employee productivity.
- It helps to detect security threats and incidents in real time, allowing for timely responses. (Correct answer)
- It helps to track the organization’s expenses.
- It helps increase organizational revenue.
Correct answer: It helps to detect security threats and incidents in real time, allowing for timely responses.
Continuous monitoring is vital in security program management because the threat landscape is constantly evolving. It involves ongoing surveillance of an organization's systems, networks, and data for security threats and incidents in real time. This continuous vigilance allows for the immediate detection of suspicious activities, enabling timely responses to mitigate potential breaches and maintain a strong security posture.
Question 123: Which audit sampling method selects items based on their monetary value, giving higher-value transactions a greater probability of selection?
- Judgment sampling
- Systematic sampling
- Stratified random sampling
- Monetary unit sampling (Correct answer)
Correct answer: Monetary unit sampling
Monetary unit sampling (MUS) gives each dollar an equal probability of selection, so higher-value items are more likely to be chosen.
Question 124: What is the PRIMARY purpose of a security program roadmap?
- To provide a prioritized, time-bound plan for maturing security capabilities (Correct answer)
- To list all compliance requirements the organization must meet
- To assign blame for past security failures
- To document all current security incidents
Correct answer: To provide a prioritized, time-bound plan for maturing security capabilities
A roadmap gives leadership a clear view of where the program is headed, what capabilities will be built, and when.
Question 125: Which scenario represents a violation of the EC-Council Certified CISO code of professional conduct?
- Declining work outside one's area of competence
- Misrepresenting qualifications or certification status (Correct answer)
- Reporting safety concerns to regulatory authorities
- Seeking continuing education beyond minimum requirements
Correct answer: Misrepresenting qualifications or certification status
Misrepresenting qualifications or certification status is a serious violation of professional conduct. It undermines public trust and can lead to harm when unqualified individuals perform specialized work.
Question 126: Which security governance structure places the CISO directly under the CEO, independent of IT?
- Decentralized security model
- Federated governance model
- Centralized IT governance model
- Business-aligned CISO model (Correct answer)
Correct answer: Business-aligned CISO model
The business-aligned CISO model positions the CISO as a peer of the CIO, reporting to the CEO, ensuring security independence from IT operations.
Question 127: Which of the following BEST describes a security strategy's 'strategic objective'?
- An SLA metric in a vendor contract
- A password complexity requirement in a security policy
- A broad, measurable outcome the security program aims to achieve over the planning period (Correct answer)
- A specific technical control to be implemented within 30 days
Correct answer: A broad, measurable outcome the security program aims to achieve over the planning period
Strategic objectives are high-level, measurable outcomes (e.g., 'achieve ISO 27001 certification within 2 years') that guide program direction.
Question 128: What is the primary goal of segregation of duties (SoD) as a governance control?
- Ensure all employees are cross-trained for redundancy
- Reduce the number of user accounts in the system
- Prevent any single individual from having enough access to commit and conceal fraud (Correct answer)
- Enforce least privilege by limiting access to one system per user
Correct answer: Prevent any single individual from having enough access to commit and conceal fraud
SoD ensures that critical business functions require multiple people, so no single individual can both execute and hide a fraudulent or malicious act.
Question 129: Which procurement practice BEST reduces the risk of counterfeit or tampered hardware components entering the organization's supply chain?
- Purchasing hardware only from the lowest-cost suppliers
- Using open-market procurement for cost efficiency
- Relying on vendor warranty agreements
- Sourcing hardware from authorized resellers and implementing integrity verification upon receipt (Correct answer)
Correct answer: Sourcing hardware from authorized resellers and implementing integrity verification upon receipt
Procuring from authorized resellers and verifying hardware integrity upon receipt reduces the risk of counterfeit or supply chain-compromised components.
Question 130: What is the primary purpose of encryption in CCISO security?
- To protect data confidentiality during storage and transmission (Correct answer)
- To organize data more efficiently
- To make data transfer slower
- To compress data
Correct answer: To protect data confidentiality during storage and transmission
Encryption protects data confidentiality by converting information into an unreadable format that can only be decoded with the proper key.
Question 131: A CISO is designing a tiered incident severity classification scheme. Which criterion is MOST important when assigning the highest severity tier?
- Potential impact on business-critical operations, regulatory obligations, or reputational damage (Correct answer)
- Number of helpdesk tickets generated
- Whether the incident involved an external actor
- Whether antivirus detected the threat
Correct answer: Potential impact on business-critical operations, regulatory obligations, or reputational damage
Severity classification must be anchored to business impact, regulatory exposure, and reputational risk, not merely technical indicators or source of attack.
Question 132: When building a security program in a decentralized organization, what is the MOST effective model for maintaining consistent security standards?
- Each business unit independently defines its own security standards
- Outsourcing all security responsibilities to a single MSSP
- Fully centralized security team that controls all decisions
- Federated model with central policy and local implementation accountability (Correct answer)
Correct answer: Federated model with central policy and local implementation accountability
A federated model balances central policy consistency with local flexibility, which is essential in organizations with autonomous business units.
Question 133: What is the value of continuing education in business continuity for CCISO professionals?
- It keeps professionals current with evolving standards and practices (Correct answer)
- It is only needed for recertification
- It replaces workplace experience
- It is primarily a social activity
Correct answer: It keeps professionals current with evolving standards and practices
Continuing education ensures professionals stay current with the latest developments, standards, and best practices in their field.
Question 134: What is the main objective of a security program?
- To improve customer service.
- To monitor employee performance.
- To increase revenue.
- To protect the organization’s assets, information, and systems from risks and threats. (Correct answer)
Correct answer: To protect the organization’s assets, information, and systems from risks and threats.
The primary objective of a security program is to comprehensively protect an organization's valuable assets, including its information, systems, and physical infrastructure, from various risks and threats. This involves implementing a layered defense strategy to ensure confidentiality, integrity, and availability of data. Ultimately, it aims to safeguard the organization's reputation, financial stability, and operational continuity.
Question 135: A CISO is preparing a five-year security roadmap with associated budget projections. Which financial planning technique accounts for the decreasing value of future spending in today's dollars?
- Earned value management
- Discounted cash flow (DCF) analysis (Correct answer)
- Sensitivity analysis
- Break-even analysis
Correct answer: Discounted cash flow (DCF) analysis
Discounted cash flow analysis applies discount rates to future cash outflows to express them in present value terms, enabling accurate multi-year financial comparison.
Question 136: Which cryptographic protocol provides forward secrecy by generating unique session keys for each session, so compromising one key does not expose past sessions?
- Diffie-Hellman Ephemeral (DHE) (Correct answer)
- MD5 hashing
- RSA key exchange
- AES-128 encryption
Correct answer: Diffie-Hellman Ephemeral (DHE)
DHE generates ephemeral keys per session, ensuring past session keys cannot be derived even if the long-term private key is later compromised.
Question 137: What is the best practice for maintaining security architecture performance over time?
- Outsource all maintenance
- Wait for failures before acting
- Upgrade all equipment annually
- Implement scheduled preventive maintenance (Correct answer)
Correct answer: Implement scheduled preventive maintenance
Scheduled preventive maintenance catches potential issues before they cause failures, maintaining reliability and extending equipment life.
Question 138: Which metric BEST helps a CISO demonstrate the business value of a security program to the board?
- Number of vulnerabilities patched per quarter
- Mean time to detect (MTTD) in hours
- Return on Security Investment (ROSI) (Correct answer)
- Percentage of systems with antivirus installed
Correct answer: Return on Security Investment (ROSI)
ROSI translates security investments into financial terms that resonate with business leadership, demonstrating cost-benefit value.
Question 139: Which of the following BEST describes the purpose of a Statement of Applicability (SoA) in ISO 27001?
- Lists applicable controls and justifies inclusions and exclusions (Correct answer)
- Outlines the business continuity plan
- Defines the scope of the ISMS boundary
- Documents the organization's risk appetite
Correct answer: Lists applicable controls and justifies inclusions and exclusions
The SoA documents which Annex A controls are applicable, their implementation status, and the justification for including or excluding each control.
Question 140: A CISO is implementing a chargeback model where security costs are allocated back to business units. What is the primary governance benefit of this approach?
- It eliminates the need for a centralized security budget
- It reduces the overall security budget requirement
- It creates business unit accountability for security spending and incentivizes risk-reducing behavior (Correct answer)
- It transfers legal liability to individual business units
Correct answer: It creates business unit accountability for security spending and incentivizes risk-reducing behavior
Chargeback models make business units financially accountable for security costs, creating incentives to reduce risky behaviors that drive security spending.
Question 141: Which metric type directly demonstrates the business value of security investments to executive stakeholders?
- Firewall rule count
- Cost avoidance from prevented incidents (Correct answer)
- Number of vulnerability scans completed
- Patch compliance percentage
Correct answer: Cost avoidance from prevented incidents
Cost avoidance metrics translate security activities into financial terms that resonate with business leadership and justify investment.
Question 142: What is the importance of legal and regulatory compliance in incident response?
- To simplify the recovery process.
- To increase organizational revenue.
- To avoid penalties and ensure legal protection.
- To ensure that proper procedures are followed and avoid legal issues. (Correct answer)
Correct answer: To ensure that proper procedures are followed and avoid legal issues.
Legal and regulatory compliance is paramount in incident response to ensure that proper procedures are followed and to avoid legal issues, fines, or reputational damage. Organizations must adhere to data breach notification laws, privacy regulations (like GDPR or CCPA), and industry-specific mandates. Compliance ensures the organization acts responsibly and protects itself from adverse legal consequences.
Question 143: What is the primary security benefit of implementing Single Sign-On (SSO) in an enterprise environment?
- It reduces password fatigue and the risk of weak or reused passwords across multiple applications (Correct answer)
- It automatically encrypts all user sessions
- It prevents brute-force attacks on individual applications
- It eliminates the need for any passwords across the enterprise
Correct answer: It reduces password fatigue and the risk of weak or reused passwords across multiple applications
SSO allows users to authenticate once and access multiple applications, reducing the number of passwords users must manage and lowering the risk of weak or reused credentials.
Question 144: Under ISO/IEC 27005, the risk evaluation step is performed to:
- Implement controls selected from ISO/IEC 27002
- Document residual risk after controls are applied
- Compare risk analysis results against risk criteria to prioritize treatment (Correct answer)
- Identify all assets within scope of the ISMS
Correct answer: Compare risk analysis results against risk criteria to prioritize treatment
Risk evaluation compares the estimated risk levels against pre-established risk criteria to determine which risks require treatment and their priority.
Question 145: In EC-Council Certified CISO practice, what is the FIRST step when a safety hazard is identified in the workplace?
- Immediately secure the area and report the hazard (Correct answer)
- Wait for a supervisor to notice the issue
- Document it for the next safety audit
- Continue working and report at end of shift
Correct answer: Immediately secure the area and report the hazard
When a safety hazard is identified, the immediate priority is to secure the area to prevent injury and report the hazard through proper channels. Delaying action increases the risk of incidents.
Question 146: Which planning technique helps a CISO identify which security initiatives are time-sensitive versus those that can be sequenced later?
- Critical path method (CPM) (Correct answer)
- Business impact analysis (BIA)
- Risk heat map generation
- Vulnerability severity scoring (CVSS)
Correct answer: Critical path method (CPM)
Critical path method identifies the sequence of dependent tasks that determine the minimum time to complete a strategic initiative.
Question 147: What role does incident response play in information security management?
- It helps manage and recover from security incidents. (Correct answer)
- It focuses only on preventing physical theft.
- It focuses on customer service improvements.
- It monitors employee productivity.
Correct answer: It helps manage and recover from security incidents.
Incident response is a crucial component of information security management that provides a structured approach to detecting, analyzing, containing, eradicating, and recovering from security breaches. Having a well-defined incident response plan minimizes the damage caused by security incidents and ensures a swift return to normal operations. This capability is essential for maintaining trust, compliance, and business continuity.
Question 148: What is the key benefit of evidence-based decision making in CCISO management?
- It reduces reliance on data
- It speeds up all processes
- It eliminates all risk
- It improves accuracy and reduces bias in decisions (Correct answer)
Correct answer: It improves accuracy and reduces bias in decisions
Evidence-based decision making uses data and research to improve the accuracy of decisions and reduce the influence of personal bias.
Question 149: A CISO negotiates a multi-year enterprise license agreement (ELA) for a security platform. What financial advantage does an ELA typically provide over annual licensing?
- Eliminates all maintenance and support costs
- Allows unlimited users without additional charges in all cases
- Guarantees feature parity with the vendor's latest release
- Provides price certainty and typically lower per-unit cost over the contract term (Correct answer)
Correct answer: Provides price certainty and typically lower per-unit cost over the contract term
ELAs lock in pricing for the contract term, protecting against year-over-year price increases and typically offering volume discounts that reduce total cost compared to annual renewals.
Question 150: Which skill is most critical for effective strategic planning?
- Speed of decision-making
- Individual work preferences
- Communication and stakeholder engagement (Correct answer)
- Technical expertise alone
Correct answer: Communication and stakeholder engagement
Communication and stakeholder engagement are essential because management success depends on effectively coordinating with and influencing others.
Question 151: An organization relies on a single vendor for 80% of its critical IT infrastructure. Which risk concept does this BEST illustrate?
- Vendor lock-in and single point of failure (Correct answer)
- Supplier diversity compliance
- Regulatory concentration limits
- Economies of scale
Correct answer: Vendor lock-in and single point of failure
Over-reliance on a single vendor creates vendor lock-in and a single point of failure, significantly elevating operational and continuity risk.
EC-Council Certified CISO (CCISO) Exam
The CCISO certification recognizes the experience and knowledge required to develop and execute an information security management strategy at the executive level.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds