
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 5
Application Security CCISO Practice Questions (Page 10)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 65 practice questions to prepare you well beyond it. (estimate)
65questions here
13free pages
15concepts
Questions 46–50
- 46
A development team wants to automate security checks in their CI/CD pipeline. They currently have a SAST tool that runs on every commit. What additional step should they add to ensure that security testing is not bypassed?
Select an answer first - 47
What is the primary purpose of hashing a password before storing it in a database?
Select an answer first - 48
Which of the following is listed in the OWASP Top 10 as a critical web application security risk?
Select an answer first - 49
A public API allows users to retrieve their own profile data. A security review finds that the API does not validate that the authenticated user owns the requested resource. Which vulnerability is this, and what is the best fix?
Select an answer first - 50
A web application allows users to post comments that are displayed to other users. A penetration test revealed that a user can submit a comment containing JavaScript that executes in other users' browsers. The application uses a framework that automatically encodes output, but the development team has disabled this feature in some places for performance reasons. What is the most effective control to prevent this vulnerability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.