
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 5
Application Security CCISO Practice Questions (Page 12)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 65 practice questions to prepare you well beyond it. (estimate)
65questions here
13free pages
15concepts
Questions 56–60
- 56
What is the difference between authentication and authorization in application security?
Select an answer first - 57
Which application security testing method analyzes source code without executing the application?
Select an answer first - 58
Which of the following is a structured threat modeling technique commonly used to identify and prioritize threats?
Select an answer first - 59
Which of the following is an example of an application security governance activity?
Select an answer first - 60
A financial services company is deploying a new customer-facing web application. The security team has completed threat modeling and identified SQL injection and cross-site scripting as top risks. The team wants to catch these vulnerabilities early in the development process, before the application is deployed, and also verify that the fixes are effective. Which combination of testing approaches best meets this need?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.