
EC-CouncilAssociate C|CISO
Domain 4Objective 5
Application Security ACCISO Practice Questions (Page 9)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
11concepts
Questions 41–45
- 41
A team is designing a new online payment system. During threat modeling, they use STRIDE to categorize threats. They identify that an attacker could tamper with the transaction amount in transit. Which STRIDE category does this threat fall under, and what is the most appropriate mitigation?
Select an answer first - 42
A large organization is adopting a secure SDLC. They have a legacy application that was developed without security considerations and is now critical to business operations. The team must integrate security without a full rewrite. Which approach best balances risk reduction and business continuity?
Select an answer first - 43
What is the purpose of aligning application security practices with regulatory requirements?
Select an answer first - 44
An organization is adopting DevSecOps and wants to automate security checks in its CI/CD pipeline without slowing down developers. The team needs to catch common vulnerabilities early while minimizing false positives. Which approach best balances speed and security?
Select an answer first - 45
An e-commerce company has deployed a WAF in front of its web application. The security team notices that legitimate users are occasionally blocked, and some SQL injection attempts are not being detected. What should the team do first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.