
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 5
Application Security CCISO Practice Questions (Page 3)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 65 practice questions to prepare you well beyond it. (estimate)
65questions here
13free pages
15concepts
Questions 11–15
- 11
A multinational corporation has multiple business units that develop software independently. The CISO wants to implement an application security governance program that ensures compliance with internal policies and industry regulations, but also wants to avoid slowing down development. The business units have different risk appetites and development methodologies. Which governance approach is the most effective?
Select an answer first - 12
What is the purpose of application security governance?
Select an answer first - 13
A company must comply with data protection regulations that require personal data to be encrypted in transit and at rest. They are deploying a new web application in a public cloud. Which combination of controls is most appropriate?
Select an answer first - 14
What is the purpose of input validation in application security?
Select an answer first - 15
An organization is designing a microservices architecture where each service calls other services. They need to authenticate service-to-service calls without storing shared secrets in code. Which approach is most secure and manageable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.