Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilAssociate C|CISO

Domain 4Objective 4

Threat and Vulnerability Management ACCISO Practice Questions (Page 3)

Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
6concepts

Questions 11–15

  1. 11foundation · easy

    Which standardized scoring system is commonly used to assess the severity of a vulnerability based on metrics such as attack vector, complexity, and impact?

    Select an answer first
  2. 12foundation · easy

    Which type of threat is characterized by a prolonged, targeted cyberattack in which an intruder gains access to a network and remains undetected for an extended period, often to steal sensitive data?

    Select an answer first
  3. 13application · medium

    A regional bank's security team notices a pattern of spear-phishing emails targeting its treasury department. The emails reference recent wire-transfer procedures and include a malicious attachment. The team has limited resources and must decide where to focus its immediate defensive efforts. Which approach best aligns with threat intelligence integration and risk prioritization?

    Select an answer first
  4. 14application · medium

    A security analyst has completed a vulnerability scan and identified the following issues: a critical RCE vulnerability on an internet-facing web server, a high-severity SQL injection in an internal HR application, and a medium-severity misconfiguration on a development database. The organization has limited staff and can only remediate one issue this week. Which vulnerability should be addressed first?

    Select an answer first
  5. 15application · medium

    A regional bank has observed a series of targeted phishing emails sent to its treasury staff. The emails reference recent wire-transfer procedures and contain a malicious attachment that, when opened, establishes a covert command-and-control channel. The bank's security team suspects an advanced persistent threat (APT) group known for targeting financial institutions. Which combination of actions should the team prioritize to address this threat?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.