Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Chief Information Security Officer

Domain 4Objective 7

Vulnerability Assessments and Penetration Testing CCISO Practice Questions (Page 6)

Part of the Information Security Core Competencies domain, which makes up ~33% of our current practice bank. EC-Council does not publish an official question count, but from its 150-minute exam (~60–100 total, ~20–33 in this domain), expect 3–4 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)

57questions here
12free pages
11concepts

Questions 26–30

  1. 26application · medium

    A healthcare organization is preparing for a regulatory audit and wants to validate that its newly deployed web application firewall (WAF) and intrusion prevention system (IPS) actually block known attack patterns. The CISO authorizes a test that simulates real-world attacker behavior against the production environment, but the testers are given no credentials, no architecture diagrams, and no source code. The test must not disrupt live patient-facing services. Which type of engagement best matches this requirement?

    Select an answer first
  2. 27application · medium

    A penetration tester has been hired to assess a client's network. During the engagement, the tester discovers a critical vulnerability in a third-party application that is also used by other organizations. The client's contract does not mention disclosure of vulnerabilities to third parties. What should the tester do?

    Select an answer first
  3. 28foundation · easy

    Which statement best distinguishes a vulnerability assessment from a penetration test?

    Select an answer first
  4. 29foundation · easy

    What does the Common Vulnerability Scoring System (CVSS) provide?

    Select an answer first
  5. 30expert · hard

    A penetration testing team has successfully exploited a vulnerability in a client's web application and gained access to the application server. The team's objective is to demonstrate the potential business impact of the compromise. The client is particularly concerned about the confidentiality of customer data stored in a backend database. According to the penetration testing phases, what should the team do next?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCISO” is a trademark of its owner, used for identification only.