
EC-CouncilAssociate C|CISO
Domain 4Objective 5
Application Security ACCISO Practice Questions (Page 11)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
11concepts
Questions 51–55
- 51
Which application security testing method analyzes source code without executing the application?
Select an answer first - 52
A company has a CI/CD pipeline that builds a containerized web application. The security team wants to add automated security testing but has limited budget and time. They need to catch vulnerabilities in both the source code and the container image. Which combination of testing tools should be integrated into the pipeline?
Select an answer first - 53
A healthcare organization is developing a patient portal that handles protected health information (PHI). The compliance officer requires that security controls be integrated into every phase of the software development lifecycle. Which approach best satisfies this requirement?
Select an answer first - 54
What is the primary defense against Cross-Site Scripting (XSS) attacks?
Select an answer first - 55
Why is application security important in the software development lifecycle?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.