Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 4Objective 7

Vulnerability Assessments and Penetration Testing CCISO Practice Questions (Page 2)

Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)

57questions here
12free pages
11concepts

Questions 6–10

  1. 6expert · hard

    A penetration test is being conducted on a third-party cloud service. The CISO must ensure the test is authorized and does not violate the cloud provider's terms of service. Which step is most important before starting the test?

    Select an answer first
  2. 7expert · hard

    A CISO is planning a penetration test that will involve social engineering of employees. The test is intended to assess the effectiveness of security awareness training. The CISO must ensure the test is legally and ethically sound. Which step is essential before conducting the social engineering test?

    Select an answer first
  3. 8expert · hard

    A penetration testing team has completed an engagement and is preparing the final report. The report includes a critical finding that was successfully exploited, a high finding that could not be exploited due to a security control, and several medium findings. The client's management is focused on the critical finding and wants to allocate all resources to fix it. The CISO wants the report to guide a balanced remediation strategy. What should the report emphasize?

    Select an answer first
  4. 9foundation · easy

    Which tool is commonly used for network vulnerability scanning?

    Select an answer first
  5. 10application · medium

    A regional bank has completed a vulnerability scan of its internet-facing web application and received a report with 40 findings. The CISO asks the security team to prioritize remediation efforts for the next sprint. The team has limited patching capacity and must address the most critical issues first. The report includes a SQL injection flaw in the login form (CVSS 9.8), a missing HTTP security header (CVSS 5.3), an outdated TLS version (CVSS 7.4), and a verbose error message disclosure (CVSS 3.1). Which approach should the team take to align with industry best practices?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.