Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilAssociate C|CISO

Domain 4Objective 4

Threat and Vulnerability Management ACCISO Practice Questions (Page 5)

Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
6concepts

Questions 21–25

  1. 21expert · hard

    A multinational corporation has identified a sophisticated APT group that has been targeting its industry. The APT is known to use zero-day exploits and custom malware. The corporation has a mature vulnerability management program but is struggling to prioritize its defenses. The CISO wants to focus on the most effective approach. Which strategy is most appropriate?

    Select an answer first
  2. 22foundation · easy

    When a vendor patch for a critical vulnerability is not yet available, which remediation approach can be used to reduce the risk of exploitation in the meantime?

    Select an answer first
  3. 23expert · hard

    A security team is conducting a vulnerability assessment of a web application. They have limited time and need to identify the most critical vulnerabilities. The team has access to the application's source code and a staging environment. Which combination of methods is most efficient for this task?

    Select an answer first
  4. 24application · medium

    A security team is reviewing a threat intelligence report that describes a new phishing campaign targeting employees in the finance department. The report includes the subject lines used, the sender domains, and the malicious payloads. Which action should the team take to integrate this intelligence into their vulnerability management process?

    Select an answer first
  5. 25expert · hard

    A company has a legacy application that is critical to operations but has known vulnerabilities that cannot be patched because the vendor is out of business. The application is accessible only from the internal network. The security team must reduce risk without disrupting operations. Which combination of compensating controls is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.