
EC-CouncilAssociate C|CISO
Domain 4Objective 5
Application Security ACCISO Practice Questions (Page 10)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
11concepts
Questions 46–50
- 46
In a secure software development lifecycle (SSDLC), which activity is typically performed during the requirements phase?
Select an answer first - 47
A healthcare organization is developing a mobile app that lets patients view their lab results. The app stores data locally on the device for offline access. Which two controls are most important to protect the data at rest and ensure compliance with healthcare regulations?
Select an answer first - 48
Which security control is essential for protecting APIs from unauthorized access?
Select an answer first - 49
What is the primary purpose of application security in the software development lifecycle?
Select an answer first - 50
A multinational company is developing an application that processes personal data of EU citizens. The company must comply with GDPR. The development team wants to integrate security into the SDLC. Which practice is most directly required by GDPR for application development?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.