
EC-CouncilAssociate C|CISO
Domain 4Objective 7
Vulnerability Assessments and Penetration Testing ACCISO Practice Questions (Page 9)
Part of the Information Security Core Competencies domain, which makes up ~31% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 2–3 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 41–45
- 41
After a vulnerability scan, the analyst sees a critical finding on a web server. The finding is based on a version string that appears outdated, but the server is actually patched behind a load balancer. What should the analyst do with this finding?
Select an answer first - 42
A vulnerability scan identifies a critical remote code execution vulnerability on an internet-facing server. The server is scheduled for decommissioning in three months, and the patch requires a reboot that will cause a two-hour outage. The organization has a 99.9% uptime SLA. What is the best course of action?
Select an answer first - 43
What is a key capability of vulnerability scanning tools?
Select an answer first - 44
What is the primary objective of a penetration test?
Select an answer first - 45
A penetration test report includes a critical finding: an unauthenticated remote code execution vulnerability in a public-facing application. The remediation recommendation is to apply a vendor patch. However, the patch requires a 30-minute downtime and the application is business-critical. The client asks for an alternative remediation that does not require downtime. Which recommendation is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ACCISO” is a trademark of its owner, used for identification only.