Proper study guides for 712-50 EC-Council Certified CISO (CCISO) certified begins with preparation products which designed to deliver the by making you pass the 712-50 test at your first time. Try the free right now.
Free 712-50 Demo Online For Microsoft Certifitcation:
NEW QUESTION 1
The single most important consideration to make when developing your security program, policies, and processes is:
- A. Budgeting for unforeseen data compromises
- B. Streamlining for efficiency
- C. Alignment with the business
- D. Establishing your authority as the Security Executive
Answer: C
NEW QUESTION 2
What role should the CISO play in properly scoping a PCI environment?
- A. Validate the business units’ suggestions as to what should be included in the scoping process
- B. Work with a Qualified Security Assessor (QSA) to determine the scope of the PCI environment
- C. Ensure internal scope validation is completed and that an assessment has been done to discover all credit card data
- D. Complete the self-assessment questionnaire and work with an Approved Scanning Vendor (ASV) to determine scope
Answer: C
NEW QUESTION 3
When entering into a third party vendor agreement for security services, at what point in the process is it BEST to understand and validate the security posture and compliance level of the vendor?
- A. At the time the security services are being performed and the vendor needs access to the network
- B. Once the agreement has been signed and the security vendor states that they will need access to the network
- C. Once the vendor is on premise and before they perform security services
- D. Prior to signing the agreement and before any security services are being performed
Answer: D
NEW QUESTION 4
Which of the following is a countermeasure to prevent unauthorized database access from web applications?
- A. Session encryption
- B. Removing all stored procedures
- C. Input sanitization
- D. Library control
Answer: C
NEW QUESTION 5
Scenario: The new CISO was informed of all the Information Security projects that the section has in progress. Two projects are over a year behind schedule and way over budget.
Using the best business practices for project management, you determine that the project
correctly aligns with the organization goals. What should be verified next?
- A. Scope
- B. Budget
- C. Resources
- D. Constraints
Answer: A
NEW QUESTION 6
Involvement of senior management is MOST important in the development of:
- A. IT security implementation plans.
- B. Standards and guidelines.
- C. IT security policies.
- D. IT security procedures.
Answer: C
NEW QUESTION 7
Which of the following functions evaluates patches used to close software vulnerabilities of new systems to assure compliance with policy when implementing an information security program?
- A. System testing
- B. Risk assessment
- C. Incident response
- D. Planning
Answer: A
NEW QUESTION 8
Acme Inc. has engaged a third party vendor to provide 99.999% up-time for their online web presence and had them contractually agree to this service level agreement. What type of risk tolerance is Acme exhibiting? (choose the BEST answer):
- A. low risk-tolerance
- B. high risk-tolerance
- C. moderate risk-tolerance
- D. medium-high risk-tolerance
Answer: A
NEW QUESTION 9
The general ledger setup function in an enterprise resource package allows for setting accounting periods. Access to this function has been permitted to users in finance, the shipping department, and production scheduling. What is the most likely reason for such broad access?
- A. The need to change accounting periods on a regular basis.
- B. The requirement to post entries for a closed accounting period.
- C. The need to create and modify the chart of accounts and its allocations.
- D. The lack of policies and procedures for the proper segregation of duties.
Answer: D
NEW QUESTION 10
Scenario: Most industries require compliance with multiple government regulations and/or industry standards to meet data protection and privacy mandates.
When multiple regulations or standards apply to your industry you should set controls to meet the:
- A. Easiest regulation or standard to implement
- B. Stricter regulation or standard
- C. Most complex standard to implement
- D. Recommendations of your Legal Staff
Answer: A
NEW QUESTION 11
The security team has investigated the theft/loss of several unencrypted laptop computers containing sensitive corporate information. To prevent the loss of any additional corporate data it is unilaterally decided by the CISO that all existing and future laptop computers will be encrypted. Soon, the help desk is flooded with complaints about the slow performance of the laptops and users are upset. What did the CISO do wrong? (choose the BEST answer):
- A. Failed to identify all stakeholders and their needs
- B. Deployed the encryption solution in an inadequate manner
- C. Used 1024 bit encryption when 256 bit would have sufficed
- D. Used hardware encryption instead of software encryption
Answer: A
NEW QUESTION 12
A CISO decides to analyze the IT infrastructure to ensure security solutions adhere to the concepts of how hardware and software is implemented and managed within the organization. Which of the following principles does this best demonstrate?
- A. Alignment with the business
- B. Effective use of existing technologies
- C. Leveraging existing implementations
- D. Proper budget management
Answer: A
NEW QUESTION 13
What is the MAIN reason for conflicts between Information Technology and Information Security programs?
- A. Technology governance defines technology policies and standards while security governance does not.
- B. Security governance defines technology best practices and Information Technology governance does not.
- C. Technology Governance is focused on process risks whereas Security Governance is focused on business risk.
- D. The effective implementation of security controls can be viewed as an inhibitor to rapid Information Technology implementations.
Answer: D
NEW QUESTION 14
Which of the following is MOST important when tuning an Intrusion Detection System (IDS)?
- A. Trusted and untrusted networks
- B. Type of authentication
- C. Storage encryption
- D. Log retention
Answer: A
NEW QUESTION 15
Your incident handling manager detects a virus attack in the network of your company. You develop a signature based on the characteristics of the detected virus. Which of the following phases in the incident handling process will utilize the signature to resolve this incident?
- A. Containment
- B. Recovery
- C. Identification
- D. Eradication
Answer: D
NEW QUESTION 16
Which of the following is a critical operational component of an Incident Response Program (IRP)?
- A. Weekly program budget reviews to ensure the percentage of program funding remains constant.
- B. Annual review of program charters, policies, procedures and organizational agreements.
- C. Daily monitoring of vulnerability advisories relating to your organization’s deployed technologies.
- D. Monthly program tests to ensure resource allocation is sufficient for supporting the needs of the organization
Answer: C
NEW QUESTION 17
An audit was conducted and many critical applications were found to have no disaster recovery plans in place. You conduct a Business Impact Analysis (BIA) to determine impact to the company for each application. What should be the NEXT step?
- A. Determine the annual loss expectancy (ALE)
- B. Create a crisis management plan
- C. Create technology recovery plans
- D. Build a secondary hot site
Answer: C
NEW QUESTION 18
Which of the following international standards can be BEST used to define a Risk Management process in an organization?
- A. National Institute for Standards and Technology 800-50 (NIST 800-50)
- B. International Organization for Standardizations – 27005 (ISO-27005)
- C. Payment Card Industry Data Security Standards (PCI-DSS)
- D. International Organization for Standardizations – 27004 (ISO-27004)
Answer: B
NEW QUESTION 19
A method to transfer risk is to:
- A. Implement redundancy
- B. move operations to another region
- C. purchase breach insurance
- D. Alignment with business operations
Answer: C
100% Valid and Newest Version 712-50 Questions & Answers shared by prep-labs.com, Get Full Dumps HERE: https://www.prep-labs.com/dumps/712-50/ (New 343 Q&As)