
EC-CouncilCertified Chief Information Security Officer
Domain 4Objective 5
Application Security CCISO Practice Questions (Page 6)
Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 65 practice questions to prepare you well beyond it. (estimate)
65questions here
13free pages
15concepts
Questions 26–30
- 26
A developer is writing a web form that accepts a user's name and later displays it on a confirmation page. The application uses a modern framework with automatic output encoding. Which additional control is most important to prevent stored XSS?
Select an answer first - 27
A security architect is leading a threat modeling exercise for a new online payment application. The team has limited time and must prioritize which threats to address. The application will handle credit card data and is subject to PCI DSS. The team has identified several threats, including SQL injection, cross-site scripting, insecure deserialization, and business logic flaws. Which threat should be prioritized first, considering both likelihood and impact?
Select an answer first - 28
A mobile app for a retail loyalty program stores the user's loyalty points balance and personal profile data on the device. The app also communicates with a backend server over HTTPS. A security review found that the app's local database is unencrypted and that the app uses a custom encryption scheme for network traffic instead of TLS. Which two issues must be fixed?
Select an answer first - 29
What is the primary defense against Cross-Site Scripting (XSS) attacks?
Select an answer first - 30
What is the primary goal of the containment phase in application incident response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.