Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilAssociate C|CISO

Domain 4Objective 4

Threat and Vulnerability Management ACCISO Practice Questions (Page 2)

Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
6concepts

Questions 6–10

  1. 6expert · hard

    A security manager is designing a vulnerability management reporting process. The process must provide actionable information to different audiences: the executive team, IT operations, and the security team. Which approach is most effective?

    Select an answer first
  2. 7foundation · easy

    What is an indicator of compromise (IoC) in the context of threat intelligence?

    Select an answer first
  3. 8application · medium

    A company is deploying a new web application and wants to identify vulnerabilities that could be exploited by an attacker. The team has access to the source code and a staging environment. Which combination of methods would provide the most comprehensive vulnerability identification?

    Select an answer first
  4. 9application · medium

    A vulnerability scan identifies a missing security patch on a server that hosts a critical database. The patch requires a reboot, which would cause downtime. The database cannot be taken offline during business hours. Which remediation approach is most appropriate?

    Select an answer first
  5. 10application · medium

    A security analyst has identified the following vulnerabilities in a corporate environment: - A critical remote code execution (RCE) vulnerability in an internet-facing web server with a CVSS score of 9.8, but the server is scheduled for decommissioning in two months. - A high-severity SQL injection flaw in an internal customer database that is actively used by the sales team. - A medium-severity misconfiguration in a firewall that allows unnecessary inbound traffic to a non-critical development network. Given limited remediation resources, which vulnerability should be addressed first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.