
EC-CouncilAssociate C|CISO
Domain 4Objective 7
Vulnerability Assessments and Penetration Testing ACCISO Practice Questions (Page 8)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 36–40
- 36
A vulnerability scan of a mixed environment (Windows and Linux servers) produces a large number of findings. The analyst notices that many findings are duplicates or false positives due to the scanner's configuration. The analyst has limited time to review the results. Which approach best ensures the final report is accurate and actionable?
Select an answer first - 37
Which phase of penetration testing involves gathering information about the target without actively engaging with it?
Select an answer first - 38
A company wants to assess the security of its external perimeter from an attacker's perspective. They provide the testing team with no prior knowledge of the network, but they do authorize the test. Which type of penetration test is being conducted?
Select an answer first - 39
What is the primary purpose of a vulnerability assessment?
Select an answer first - 40
A vulnerability management team is planning a quarterly assessment. They must avoid disrupting business-critical systems and ensure the report is actionable. Which sequence of steps best aligns with the vulnerability assessment process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.