
EC-CouncilAssociate C|CISO
Domain 4Objective 7
Vulnerability Assessments and Penetration Testing ACCISO Practice Questions (Page 5)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 21–25
- 21
After a vulnerability assessment, a security analyst has a list of findings. The analyst must write a report for both technical staff and senior management. Which approach best meets the needs of both audiences?
Select an answer first - 22
During a penetration test, the tester discovers that the target network uses a new endpoint protection platform that blocks common exploitation techniques. The tester must find an alternative way to exploit a vulnerability without being detected. Which phase of the penetration test is the tester in, and what is the best approach?
Select an answer first - 23
During a penetration test, the tester gains access to a low-privileged account on a Windows server. The tester wants to escalate privileges to domain administrator. The tester has already enumerated the domain and identified a misconfigured service running as SYSTEM. Which phase and tool combination is most appropriate?
Select an answer first - 24
A penetration tester is performing a web application test. The tester has identified a potential SQL injection vulnerability in a login form. To confirm the vulnerability without causing damage, the tester wants to send a payload that will not modify data. Which tool and technique is most appropriate?
Select an answer first - 25
What is the purpose of the post-exploitation phase in a penetration test?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.