Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 4Objective 5

Application Security CCISO Practice Questions (Page 9)

Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 65 practice questions to prepare you well beyond it. (estimate)

65questions here
13free pages
15concepts

Questions 41–45

  1. 41expert · hard

    A company is developing a microservices-based application with many internal APIs. The security team wants to automate security testing in the CI/CD pipeline. They have a limited budget and need to choose between SAST, DAST, and IAST. The team wants to catch vulnerabilities as early as possible, but also wants to reduce false positives that slow down development. Which approach is the most balanced?

    Select an answer first
  2. 42application · medium

    A software company is adopting DevSecOps and wants to integrate security testing into its CI/CD pipeline. The pipeline currently builds the application, runs unit tests, and deploys to a test environment. The security team wants to automatically block the build if critical vulnerabilities are found, but allow the pipeline to continue for low-severity issues. Which approach best achieves this goal?

    Select an answer first
  3. 43expert · hard

    A company is building a new customer portal that will be accessed by both internal employees and external customers. The portal will integrate with an existing identity provider (IdP) that supports SAML and OAuth 2.0. The security team requires that external customers use multi-factor authentication (MFA), but internal employees already use MFA via the corporate IdP. The portal also exposes a REST API for mobile clients. Which authentication architecture is the most appropriate?

    Select an answer first
  4. 44expert · hard

    A company's web application was breached through a vulnerability in a third-party library. The incident response team has contained the breach and restored services. The CISO wants to update the incident response plan to better handle similar incidents in the future. The team has identified that the library was outdated and that the application did not have a process for tracking library versions. Which improvement should be prioritized?

    Select an answer first
  5. 45foundation · easy

    Which of the following is a common method for authenticating API clients?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.