
EC-CouncilAssociate C|CISO
Domain 4Objective 4
Threat and Vulnerability Management ACCISO Practice Questions (Page 1)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
6concepts
Questions 1–5
- 1
A security manager needs to report to the board on the effectiveness of the vulnerability management program. Which metric would best demonstrate the program's impact on reducing risk?
Select an answer first - 2
Which vulnerability identification method involves an authorized, simulated attack on a system to actively exploit weaknesses and determine the real-world impact of a compromise?
Select an answer first - 3
A manufacturing company subscribes to a threat intelligence feed that reports a new ransomware family targeting industrial control systems (ICS). The feed includes indicators of compromise (IOCs) such as command-and-control (C2) domains and file hashes. The security team wants to proactively defend against this threat. Which action should the team take first?
Select an answer first - 4
A security team is planning a penetration test of a critical application. The test must identify exploitable vulnerabilities without causing downtime. The team has a limited time window and must choose between an automated vulnerability scan and a manual penetration test. Which approach is most appropriate?
Select an answer first - 5
Which remediation strategy involves applying a vendor-supplied update to fix a known vulnerability in a software product?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.