
EC-CouncilAssociate C|CISO
Domain 4Objective 7
Vulnerability Assessments and Penetration Testing ACCISO Practice Questions (Page 11)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 51–53
- 51
A security manager must choose between a black-box and a white-box penetration test for a critical application. The budget is limited, and the goal is to identify as many vulnerabilities as possible within the time constraint. Which approach is more appropriate and why?
Select an answer first - 52
Which step in a vulnerability assessment involves defining the systems, networks, and applications that will be examined?
Select an answer first - 53
An organization needs to continuously monitor its web applications for known vulnerabilities such as SQL injection and cross-site scripting. The team wants automated scanning integrated into their CI/CD pipeline. Which tool is most appropriate for this requirement?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ACCISO
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.