Official Bank 0/637

EC-Council Certified CISO (CCISO) Exam (712-50) - EC-Council Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
637 Total Questions
1
Question
A consultant is hired to do physical penetration testing at a large financial company. In the first day of his assessment, the consultant goes to the company’s building dressed like an electrician and waits in the lobby for an employee to pass through the main access gate, then the consultant follows the employee behind to get into the restricted area. Which type of attack did the consultant perform?
Options
A Shoulder surfing
B Tailgating
C Social engineering
D Mantrap
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
You have recently drafted a revised information security policy. From whom should you seek endorsement in order to have the GREATEST chance for adoption and implementation throughout the entire organization?
Options
A Chief Information Security Officer
B Chief Information Officer
C Chief Executive Officer
D Chief Legal Counsel
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Management] Scenario: The new CISO was informed of all the Information Security projects that the section has in progress. Two projects are over a year behind schedule and way over budget. Using the best business practices for project management, you determine that the project correctly aligns with the organization goals. What should be verified next?
Options
A Constraints
B Scope
C Budget
D Resources
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
To have accurate and effective information security policies how often should the CISO review the organization policies?
Options
A Every 6 months
B Quarterly
C Before an audit
D At least once a year
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
SCENARIO: A CISO has several two-factor authentication systems under review and selects the one that is most sufficient and least costly. The implementation project planning is completed and the teams are ready to implement the solution. The CISO then discovers that the product it is not as scalable as originally thought and will not fit the organization’s needs. The CISO is unsure of the information provided and orders a vendor proof of concept to validate the system’s scalability. This demonstrates which of the following?
Options
A An approach that allows for minimum budget impact if the solution is unsuitable
B A methodology-based approach to ensure authentication mechanism functions
C An approach providing minimum time impact to the implementation schedules
D A risk-based approach to determine if the solution is suitable for investment
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.