Certified Chief Information Security Officer (CCISO) Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 216 questions. Use the simulator for timed and flashcard mode.

Try Simulator

712-50 Sample Questions

  1. Question 1

    Q1

    As the CISO of a multinational financial institution, you are presenting the annual information security strategy to the Board of Directors. The Board Chair questions why the proposed budget for 'Risk Management' has increased by 40% despite no significant security incidents occurring in the previous fiscal year. Which response best demonstrates alignment between security governance and business objectives?

    Show answer & explanation

    Correct answer: B

    This is the optimal answer because it ties the security investment directly to the Board's risk appetite and the business goal of expansion. It demonstrates that security is a business enabler rather than just a cost center or technical necessity.

  2. Question 2

    Q2

    A global healthcare provider is acquiring a smaller regional hospital network. During the due diligence phase, you identify that the target company uses a legacy EMR system that cannot be patched against several critical vulnerabilities. The business strategy relies on integrating this network within 90 days. What is the most appropriate governance approach to handle this risk?

    Show answer & explanation

    Correct answer: C

    In an M&A scenario where business drivers are strong, the CISO must find a way to enable the business while managing risk. Implementing strong compensating controls (segmentation, virtual patching) allows operations to continue safely while formally documenting the risk ensures governance transparency.

  3. Question 3

    Q3

    You are establishing a new Enterprise Risk Management (ERM) framework. You need to define the process for risk treatment decisions. Review the diagram below representing the decision logic. Which logic flow correctly represents the standard risk treatment methodology based on ISO 31000 principles?

    flowchart TD Start[Risk Identified] --> Assess{Risk > Appetite?} Assess -->|No| A[Monitor] Assess -->|Yes| Cost{Cost of Control < Impact?} Cost -->|Yes| B[Treat/Mitigate] Cost -->|No| Crit{Is Risk Critical?} Crit -->|Yes| C[Transfer/Avoid] Crit -->|No| D[Accept]
    Show answer & explanation

    Correct answer: A

    The diagram correctly follows standard risk management logic: If risk exceeds appetite, we check if mitigation is cost-effective. If yes, we mitigate. If no (too expensive), we check criticality. If critical, we must transfer (insurance) or avoid (stop activity). If not critical and too expensive to fix, we formally accept.

  4. Question 4

    Q4

    Which of the following documents is the PRIMARY source for an external auditor to determine if an organization's security controls are operating effectively over a period of time?

    Show answer & explanation

    Correct answer: C

    For an audit testing 'operating effectiveness' (like SOC 2 Type II), the auditor requires evidence samples that span the entire audit period to prove controls functioned continuously, not just at a single point in time.

  5. Question 5

    Q5Multiple answers

    A CISO is designing a Key Performance Indicator (KPI) dashboard for the executive team. The goal is to measure the efficiency of the Incident Response (IR) team. Which TWO metrics would provide the most meaningful insight into operational efficiency? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

    MTTD measures how long it takes to discover a threat. Lowering this indicates better monitoring efficiency.

    MTTR measures the speed of recovery after detection. It directly reflects the efficiency of the response process.

  6. Question 6

    Q6

    Case Study:

    Scenario:
    A retail organization is migrating its e-commerce platform to a public cloud provider. The CISO is concerned about the 'Shared Responsibility Model'. The development team wants to use a Function-as-a-Service (FaaS) / Serverless architecture to reduce operational overhead. They plan to process credit card transactions directly within these functions.

    Constraint:
    The organization must remain PCI DSS compliant. The cloud provider is PCI DSS certified.

    Question:
    In this Serverless architecture, which security control remains the SOLE responsibility of the customer (the retail organization)?

    Show answer & explanation

    Correct answer: C

    In a FaaS/Serverless model, the cloud provider manages physical security, OS patching, and network infrastructure. The customer is responsible for the security of their code (application logic), data, and the IAM permissions granted to the functions.

  7. Question 7

    Q7

    True or False: In a robust Third-Party Risk Management (TPRM) program, obtaining a vendor's SOC 2 Type II report eliminates the need for the organization to define its own security requirements in the Master Services Agreement (MSA).

    Show answer & explanation

    Correct answer: B

    False. A SOC 2 report validates the vendor's controls against trust principles, but the MSA is a legal contract that must specify the organization's specific requirements, right to audit, breach notification timelines, and SLAs, which the SOC report does not legally enforce.

  8. Question 8

    Q8

    An organization is calculating the Return on Security Investment (ROSI) for a new Data Loss Prevention (DLP) solution.

    Given:

    • Annual Loss Expectancy (ALE) without DLP: $1,000,000
    • Estimated mitigation percentage: 80%
    • Annual cost of DLP solution: $150,000

    What is the ROSI percentage?

    Show answer & explanation

    Correct answer: A

    Calculation:
    Savings = ALE * Mitigation = $1,000,000 * 0.80 = $800,000.
    Net Benefit = Savings - Cost = $800,000 - $150,000 = $650,000.
    ROSI = (Net Benefit / Cost) * 100 = ($650,000 / $150,000) * 100 = 433.33%.

  9. Question 9

    Q9

    You are reviewing the Identity and Access Management (IAM) architecture for a hybrid environment. The organization wants to implement Single Sign-On (SSO) across on-premise Active Directory and multiple cloud SaaS applications. Which protocol is the industry standard for exchanging authentication and authorization data between an Identity Provider (IdP) and a Service Provider (SP) in this context?

    Show answer & explanation

    Correct answer: B

    SAML is the standard XML-based protocol for exchanging authentication and authorization data between an Identity Provider (IdP) and a Service Provider (SP), specifically designed for web-based SSO scenarios.

  10. Question 10

    Q10

    The internal audit team has issued a finding regarding 'Excessive Administrative Privileges' on the corporate network. The IT Director argues that the administrators need these rights to perform their daily tasks efficiently. What is the CISO's best course of action to resolve this conflict while improving security?

    Show answer & explanation

    Correct answer: B

    This is the optimal solution. It addresses the audit finding (reducing standing excessive privileges) while addressing the IT Director's need for efficiency by allowing access when needed (JIT) without permanent admin rights.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the 712-50 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 216 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon