
EC-CouncilAssociate C|CISO
Domain 4Objective 4
Threat and Vulnerability Management ACCISO Practice Questions (Page 2)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
6concepts
Questions 6–10
- 6
A security manager is designing a vulnerability management reporting process. The process must provide actionable information to different audiences: the executive team, IT operations, and the security team. Which approach is most effective?
Select an answer first - 7
What is an indicator of compromise (IoC) in the context of threat intelligence?
Select an answer first - 8
A company is deploying a new web application and wants to identify vulnerabilities that could be exploited by an attacker. The team has access to the source code and a staging environment. Which combination of methods would provide the most comprehensive vulnerability identification?
Select an answer first - 9
A vulnerability scan identifies a missing security patch on a server that hosts a critical database. The patch requires a reboot, which would cause downtime. The database cannot be taken offline during business hours. Which remediation approach is most appropriate?
Select an answer first - 10
A security analyst has identified the following vulnerabilities in a corporate environment: - A critical remote code execution (RCE) vulnerability in an internet-facing web server with a CVSS score of 9.8, but the server is scheduled for decommissioning in two months. - A high-severity SQL injection flaw in an internal customer database that is actively used by the sales team. - A medium-severity misconfiguration in a firewall that allows unnecessary inbound traffic to a non-critical development network. Given limited remediation resources, which vulnerability should be addressed first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.