
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 5
Application Security CCISO Practice Questions (Page 2)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 65 practice questions to prepare you well beyond it. (estimate)
65questions here
13free pages
15concepts
Questions 6–10
- 6
In the Secure Software Development Lifecycle (SSDLC), which activity is typically performed during the requirements phase?
Select an answer first - 7
A web application allows users to upload profile pictures. The security team is concerned about malicious file uploads leading to remote code execution. Which set of controls should be implemented?
Select an answer first - 8
A company's web application was compromised through a SQL injection vulnerability. The incident response team has confirmed that the attacker exfiltrated a database of customer records. The CISO wants to ensure that the incident response plan is updated to prevent similar issues in the future. Which action should be included in the post-incident review?
Select an answer first - 9
Which of the following is an example of a robust authentication mechanism?
Select an answer first - 10
A company exposes a REST API for its mobile app. The API currently has no authentication and is being abused by bots. The team needs to ensure that only legitimate users can access the API and that the API is not overwhelmed. Which two controls should be implemented together?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.