
EC-CouncilAssociate C|CISO
Domain 4Objective 5
Application Security ACCISO Practice Questions (Page 5)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
11concepts
Questions 21–25
- 21
Which threat modeling methodology uses a diagram to represent data flows, trust boundaries, and entry points?
Select an answer first - 22
A development team is writing a Java web application that accepts user input and displays it on a dashboard. The security architect has mandated that all output be encoded. Which secure coding practice is the team applying to mitigate a specific OWASP Top 10 risk?
Select an answer first - 23
A team is threat modeling a new application that handles sensitive user data. They have limited time and must prioritize which threats to address. The application uses a third-party authentication service and stores data in a cloud database. Which approach best prioritizes threats?
Select an answer first - 24
A company exposes a REST API for its mobile app. The security team is concerned about broken object level authorization (BOLA), where users can access other users' data by changing an ID in the request. Which control should be implemented to directly prevent this vulnerability?
Select an answer first - 25
A DevOps team wants to implement DevSecOps in their CI/CD pipeline. They face a conflict: developers want fast feedback, while the security team wants comprehensive testing before release. The team has a limited number of security testing licenses. Which strategy best resolves this conflict?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.