
Apr-2024 Download Free Latest Exam 712-50 Certified Sample Questions
Prepare for your exam certification with our 712-50 Certified EC-COUNCIL
NEW QUESTION # 36
A person in your security team calls you at night and informs you that one of your web applications is potentially under attack from a cross-site scripting vulnerability.
What do you do?
- A. tell him to analyze the problem, preserve the evidence and provide a full analysis and report.
- B. tell him to invoke the incident response process
- C. tell him to call the police
- D. tell him to shut down the server
Answer: B
NEW QUESTION # 37
Risk is defined as:
- A. Threat times vulnerability divided by control
- B. Advisory plus capability plus vulnerability
- C. Quantitative plus qualitative impact
- D. Asset loss times likelihood of event
Answer: A
NEW QUESTION # 38
A security manager has created a risk program. Which of the following is a critical part of ensuring the program is successful?
- A. Ensuring developers include risk control comments in code
- B. Providing a risk program governance structure
- C. Creating risk assessment templates based on specific threats
- D. Allowing for the acceptance of risk for regulatory compliance requirements
Answer: B
NEW QUESTION # 39
Which wireless encryption technology makes use of temporal keys?
- A. Wireless Equivalence Protocol (WEP)
- B. Extensible Authentication Protocol (EAP)
- C. Wifi Protected Access version 2 (WPA2)
- D. Wireless Application Protocol (WAP)
Answer: C
NEW QUESTION # 40
When selecting a security solution with reoccurring maintenance costs after the first year (choose the BEST answer):
- A. Communicate future operating costs to the CIO/CFO and seek commitment from them to ensure the new solution's continued use
- B. Defer selection until the market improves and cash flow is positive
- C. The CISO should cut other essential programs to ensure the new solution's continued use
- D. Implement the solution and ask for the increased operating cost budget when it is time
Answer: A
NEW QUESTION # 41
Which of the following is a major benefit of applying risk levels?
- A. Risk appetite increase within the organization once the levels are understood
- B. Risk management governance becomes easier since most risks remain low once mitigated
- C. Resources are not wasted on risks that are already managed to an acceptable level
- D. Risk budgets are more easily managed due to fewer due to fewer identified risks as a result of using a methodology
Answer: C
NEW QUESTION # 42
Providing oversight of a comprehensive information security program for the entire organization is the primary responsibility of which group under the InfoSec governance framework?
- A. Senior Executives
- B. Office of the General Counsel
- C. Office of the Auditor
- D. All employees and users
Answer: A
NEW QUESTION # 43
The MOST common method to get an unbiased measurement of the effectiveness of an Information Security Management System (ISMS) is to_________________________.
- A. assign the responsibility to the team responsible for the management of the controls
- B. perform an independent audit of the security controls
- C. assign the responsibility to the information security team
- D. create operational reports on the effectiveness of the controls.
Answer: B
Explanation:
Explanation
NEW QUESTION # 44
Scenario: Most industries require compliance with multiple government regulations and/or industry standards to meet data protection and privacy mandates.
When multiple regulations or standards apply to your industry you should set controls to meet the___________________________.
- A. Stricter regulation or standard
- B. Easiest regulation or standard to implement
- C. Most complex standard
- D. Recommendations of your Legal Staff
Answer: B
Explanation:
Explanation
NEW QUESTION # 45
A CISO wants to change the defense strategy to ward off attackers. To accomplish this the CISO is looking to a strategy where attackers are lured into a zone of a safe network where attackers can be monitored, controlled, quarantined, or eradicated.
- A. Integrated security controls
- B. Moderate investment
- C. Passive monitoring
- D. Dynamic deception
Answer: D
NEW QUESTION # 46
Scenario: Most industries require compliance with multiple government regulations and/or industry standards to meet data protection and privacy mandates.
When multiple regulations or standards apply to your industry you should set controls to meet the:
- A. Stricter regulation or standard
- B. Easiest regulation or standard to implement
- C. Most complex standard to implement
- D. Recommendations of your Legal Staff
Answer: B
NEW QUESTION # 47
From the CISO's perspective in looking at financial statements, the statement of retained earnings of an organization:
- A. Represents the sum of all capital expenditures
- B. Represents the percentage of earnings that could in part be used to finance future security controls
- C. Has a direct correlation with the CISO's budget
- D. Represents, in part, the savings generated by the proper acquisition and implementation of security controls
Answer: B
NEW QUESTION # 48
What is the primary reason for performing vendor management?
- A. To establish a vendor selection process
- B. To understand the risk coverage that are being mitigated by the vendor
- C. To document the relationship between the company and the vendor
- D. To define the partnership for long-term success
Answer: B
NEW QUESTION # 49
Which of the following is the MOST important for a CISO to understand when identifying threats?
- A. How vulnerabilities can potentially be exploited in systems that impact the organization
- B. How the incident management team prepares to handle an attack
- C. How the firewall and other security devices are configured to prevent attacks
- D. How the security operations team will behave to reported incidents
Answer: A
NEW QUESTION # 50
Physical security measures typically include which of the following components?
- A. Strong password, Biometric, Common Access Card
- B. Physical, Technical, Operational
- C. Operational, Biometric, Physical
- D. Technical, Strong Password, Operational
Answer: B
NEW QUESTION # 51
You work as a project manager for TYU project. You are planning for risk mitigation. You need to quickly identify high-level risks that will need a more in-depth analysis.
Which of the following activities will help you in this?
- A. Qualitative analysis
- B. Risk mitigation
- C. Estimate activity duration
- D. Quantitative analysis
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION # 52
Which of the following statements below regarding Key Performance indicators (KPIs) are true?
- A. They are a strictly quantitative measure of success
- B. They should be standard throughout the organization versus domain-specific so they are more easily correlated
- C. They are a strictly qualitative measure of success
- D. Development of KPI's are most useful when done independently
Answer: D
NEW QUESTION # 53
When managing an Information Security Program, which of the following is of MOST importance in order to influence the culture of an organization?
- A. Support from Legal and HR teams
- B. Compliance with local privacy regulations
- C. Alignment of security goals with business goals
- D. An independent Governance, Risk and Compliance organization
Answer: C
NEW QUESTION # 54
The new CISO was informed of all the Information Security projects that the organization has in progress. Two projects are over a year behind schedule and over budget. Using best business practices for project management you determine that the project correctly aligns with the company goals.
Which of the following needs to be performed NEXT?
- A. Verify technical resources
- B. Verify capacity constraints
- C. Verify the regulatory requirements
- D. Verify the scope of the project
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION # 55
Which of the following is considered one of the most frequent failures in project management?
- A. Insufficient resources
- B. Excessive personnel on project
- C. Failure to meet project deadlines
- D. Overly restrictive management
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION # 56
Which of the following is the MOST important reason to measure the effectiveness of an Information Security Management System (ISMS)?
- A. Better understand strengths and weaknesses of the program
- B. Meet legal requirements
- C. Better understand the threats and vulnerabilities affecting the environment
- D. Meet regulatory compliance requirements
Answer: A
NEW QUESTION # 57
Which of the following organizations is typically in charge of validating the implementation and effectiveness of security controls?
- A. Risk Management
- B. Internal/External Audit
- C. Security Administrators
- D. Security Operations
Answer: B
Explanation:
Explanation
NEW QUESTION # 58
Which of the following items of a computer system will an anti-virus program scan for viruses?
- A. Windows Process List
- B. Boot Sector
- C. Deleted Files
- D. Password Protected Files
Answer: B
NEW QUESTION # 59
Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate controls. You assign work to your staff to create or adjust existing security controls to ensure they are adequate for risk mitigation needs.
When formulating the remediation plan, what is a required input?
- A. Board of directors
- B. Patching history
- C. Latest virus definitions file
- D. Risk assessment
Answer: D
Explanation:
Scenario6
NEW QUESTION # 60
Which level of data destruction applies logical techniques to sanitize data in all user-addressable storage locations?
- A. Destroy
- B. Purge
- C. Clear
- D. Mangle
Answer: C
NEW QUESTION # 61
......
Free EC-COUNCIL 712-50 Exam 2024 Practice Materials Collection: https://www.exams4collection.com/712-50-latest-braindumps.html
712-50 Exam Info and Free Practice Test All-in-One Exam Guide Apr-2024: https://drive.google.com/open?id=1qf8cM2V3ihOW6Ohg6nKosvJxnK8GEXir
