
EC-CouncilAssociate C|CISO
Domain 4Objective 7
Vulnerability Assessments and Penetration Testing ACCISO Practice Questions (Page 1)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 1–5
- 1
A penetration testing team is asked to assess a web application that handles financial transactions. The client wants the test to focus on the most common web application vulnerabilities, such as injection, broken authentication, and cross-site scripting. Which methodology should the team use?
Select an answer first - 2
A penetration tester has completed the exploitation phase and now needs to document the findings, including the vulnerabilities exploited and the data accessed. Which phase of the penetration test is this?
Select an answer first - 3
What is the purpose of using a recognized penetration testing methodology like PTES or OSSTMM?
Select an answer first - 4
A penetration testing team is planning a test for a client that requires compliance with PCI DSS. The client wants the test to be as comprehensive as possible but also wants to minimize the risk of disrupting production systems. The team must choose a methodology that is recognized and can be tailored to the client's needs. Which methodology should they choose?
Select an answer first - 5
What is the purpose of a remediation strategy in the context of a penetration test report?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.