for EC-Council certification, Real Success Guaranteed with Updated . 100% PASS 712-50 EC-Council Certified CISO (CCISO) exam Today!

EC-Council 712-50 Free Dumps Questions Online, Read and Test Now.

NEW QUESTION 1
In which of the following cases, would an organization be more prone to risk acceptance vs. risk mitigation?

  • A. The organization uses exclusively a quantitative process to measure risk
  • B. The organization uses exclusively a qualitative process to measure risk
  • C. The organization’s risk tolerance is high
  • D. The organization’s risk tolerance is lo

Answer: C

NEW QUESTION 2
Scenario: An organization has recently appointed a CISO. This is a new role in the organization and it signals the increasing need to address security consistently at the enterprise level. This new CISO, while confident with skills and experience, is constantly on the defensive and is unable to advance the IT security centric agenda.
From an Information Security Leadership perspective, which of the following is a MAJOR concern about the CISO’s approach to security?

  • A. Lack of risk management process
  • B. Lack of sponsorship from executive management
  • C. IT security centric agenda
  • D. Compliance centric agenda

Answer: C

NEW QUESTION 3
An organization's Information Security Policy is of MOST importance because

  • A. it communicates management’s commitment to protecting information resources
  • B. it is formally acknowledged by all employees and vendors
  • C. it defines a process to meet compliance requirements
  • D. it establishes a framework to protect confidential information

Answer: A

NEW QUESTION 4
When dealing with Security Incident Response procedures, which of the following steps come FIRST when reacting to an incident?

  • A. Escalation
  • B. Recovery
  • C. Eradication
  • D. Containment

Answer: D

NEW QUESTION 5
How often should an environment be monitored for cyber threats, risks, and exposures?

  • A. Weekly
  • B. Monthly
  • C. Quarterly
  • D. Daily

Answer: D

NEW QUESTION 6
The establishment of a formal risk management framework and system authorization program is essential. The LAST step of the system authorization process is:

  • A. Contacting the Internet Service Provider for an IP scope
  • B. Getting authority to operate the system from executive management
  • C. Changing the default passwords
  • D. Conducting a final scan of the live system and mitigating all high and medium level vulnerabilities

Answer: B

NEW QUESTION 7
You have purchased a new insurance policy as part of your risk strategy. Which of the following risk strategy options have you engaged in?

  • A. Risk Avoidance
  • B. Risk Acceptance
  • C. Risk Transfer
  • D. Risk Mitigation

Answer: C

NEW QUESTION 8
Which of the following are primary concerns for management with regard to assessing internal control objectives?

  • A. Confidentiality, Availability, Integrity
  • B. Compliance, Effectiveness, Efficiency
  • C. Communication, Reliability, Cost
  • D. Confidentiality, Compliance, Cost

Answer: B

NEW QUESTION 9
In accordance with best practices and international standards, how often is security awareness training provided to employees of an organization?

  • A. High risk environments 6 months, low risk environments 12 months
  • B. Every 12 months
  • C. Every 18 months
  • D. Every six months

Answer: B

NEW QUESTION 10
Which of the following represents the BEST reason for an organization to use the Control Objectives for Information and Related Technology (COBIT) as an Information Technology (IT) framework?

  • A. It allows executives to more effectively monitor IT implementation costs
  • B. Implementation of it eases an organization’s auditing and compliance burden
  • C. Information Security (IS) procedures often require augmentation with other standards
  • D. It provides for a consistent and repeatable staffing model for technology organizations

Answer: B

NEW QUESTION 11
When updating the security strategic planning document what two items must be included?

  • A. Alignment with the business goals and the vision of the CIO
  • B. The risk tolerance of the company and the company mission statement
  • C. The executive summary and vision of the board of directors
  • D. The alignment with the business goals and the risk tolerance

Answer: D

NEW QUESTION 12
When choosing a risk mitigation method what is the MOST important factor?

  • A. Approval from the board of directors
  • B. Cost of the mitigation is less than the risk
  • C. Metrics of mitigation method success
  • D. Mitigation method complies with PCI regulations

Answer: B

NEW QUESTION 13
An access point (AP) is discovered using Wireless Equivalent Protocol (WEP). The ciphertext sent by the AP is encrypted with the same key and cipher used by its stations. What authentication method is being used?

  • A. Shared key
  • B. Asynchronous
  • C. Open
  • D. None

Answer: A

NEW QUESTION 14
Which of the following is the MOST important reason to measure the effectiveness of an Information Security Management System (ISMS)?

  • A. Meet regulatory compliance requirements
  • B. Better understand the threats and vulnerabilities affecting the environment
  • C. Better understand strengths and weaknesses of the program
  • D. Meet legal requirements

Answer: C

NEW QUESTION 15
Which of the following activities must be completed BEFORE you can calculate risk?

  • A. Determining the likelihood that vulnerable systems will be attacked by specific threats
  • B. Calculating the risks to which assets are exposed in their current setting
  • C. Assigning a value to each information asset
  • D. Assessing the relative risk facing the organization’s information assets

Answer: C

NEW QUESTION 16
Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small retail merchant but it is expected to grow to a global customer base of many millions of customers in just a few years.
This global retail company is expected to accept credit card payments. Which of the following is of MOST concern when defining a security program for this organization?

  • A. International encryption restrictions
  • B. Compliance to Payment Card Industry (PCI) data security standards
  • C. Compliance with local government privacy laws
  • D. Adherence to local data breach notification laws

Answer: B

NEW QUESTION 17
Risk appetite is typically determined by which of the following organizational functions?

  • A. Security
  • B. Business units
  • C. Board of Directors
  • D. Audit and compliance

Answer: B

NEW QUESTION 18
Quantitative Risk Assessments have the following advantages over qualitative risk assessments:

  • A. They are objective and can express risk / cost in real numbers
  • B. They are subjective and can be completed more quickly
  • C. They are objective and express risk / cost in approximates
  • D. They are subjective and can express risk /cost in real numbers

Answer: A

NEW QUESTION 19
Human resource planning for security professionals in your organization is a:

  • A. Simple and easy task because the threats are getting easier to find and correct.
  • B. Training requirement that is met through once every year user training.
  • C. Training requirement that is on-going and always changing.
  • D. Not needed because automation and anti-virus software has eliminated the threats.

Answer: C

Recommend!! Get the Full 712-50 dumps in VCE and PDF From Certifytools, Welcome to Download: https://www.certifytools.com/712-50-exam.html (New 343 Q&As Version)