Official Bank 0/974

EC-Council Certified Chief Information Security Officer (C|CISO) (712-50) - EC Council Actual Exam Questions

Last updated on May 13, 2026

97% Exam Compliance
974 Total Questions
1
Question

Which of the following is the MAIN reason to follow a formal risk management process in an organization that hosts and uses privately identifiable information (PII) as part of their business models and processes?

Options
A

Need to comply with breach disclosure laws

B

Need to transfer the risk associated with hosting PII data

C

Need to better understand the risk associated with using PII data

D

Fiduciary responsibility to safeguard credit card information

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

Which of the following conditions would be the MOST probable reason for a security project to be rejected by the executive board of an organization?

Options
A

The Net Present Value (NPV) of the project is positive

B

The NPV of the project is negative

C

The Return on Investment (ROI) is larger than 10 months

D

The ROI is lower than 10 months

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

An access point (AP) is discovered using Wireless Equivalent Protocol (WEP). The ciphertext sent by the AP is encrypted with the same key and cipher used by its stations. What authentication method is being used?

Options
A

Shared key

B

Asynchronous

C

Open

D

None

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

According to the National Institute of Standards and Technology (NIST) SP 800-40, which of the following considerations are MOST important when creating a vulnerability management program?

Options
A

Susceptibility to attack, mitigation response time, and cost

B

Attack vectors, controls cost, and investigation staffing needs

C

Vulnerability exploitation, attack recovery, and mean time to repair

D

Susceptibility to attack, expected duration of attack, and mitigation availability

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

As a new CISO at a large healthcare company you are told that everyone has to badge in to get in the building. Below your office window you notice a door that is normally propped open during the day for groups of people to take breaks outside. Upon looking closer you see there is no badge reader. What should you do?

Options
A

Nothing, this falls outside your area of influence.

B

Close and chain the door shut and send a company-wide memo banning the practice.

C

Have a risk assessment performed.

D

Post a guard at the door to maintain physical security

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.