512-50 Exam Questions
402 real 512-50 exam questions with expert-verified answers and explanations. Page 1 of 9.
- Question #1
Which of the following has the GREATEST impact on the implementation of an information security governance model?
- Question #2
From an information security perspective, information that no longer supports the main purpose of the business should be:
- Question #3
When briefing senior management on the creation of a governance process, the MOST important aspect should be:
- Question #4
Which of the following most commonly falls within the scope of an information security governance steering committee?
- Question #5
A security professional has been promoted to be the CISO of an organization. The first task is to create a security policy for this organization. The CISO creates and publishes the...
- Question #6
Which of the following is the MAIN reason to follow a formal risk management process in an organization that hosts and uses privately identifiable information (PII) as part of thei...
- Question #7
The alerting, monitoring and life-cycle management of security related events is typically handled by the
- Question #8
One of the MAIN goals of a Business Continuity Plan is to
- Question #9
When managing an Information Security Program, which of the following is of MOST importance in order to influence the culture of an organization?
- Question #10
Which of the following is considered the MOST effective tool against social engineering?
- Question #11
When dealing with Security Incident Response procedures, which of the following steps come FIRST when reacting to an incident?
- Question #12
Which of the following is of MOST importance when security leaders of an organization are required to align security to influence the culture of an organization?
- Question #13
In accordance with best practices and international standards, how often is security awareness training provided to employees of an organization?
- Question #14
Which of the following is a MAJOR consideration when an organization retains sensitive customer data and uses this data to better target the organization's products and services?
- Question #15
You have implemented a new security control. Which of the following risk strategy options have you engaged in?
- Question #16
You have purchased a new insurance policy as part of your risk strategy. Which of the following risk strategy options have you engaged in?
- Question #17
Quantitative Risk Assessments have the following advantages over qualitative risk assessments:
- Question #18
Which of the following is MOST important when dealing with an Information Security Steering committee:
- Question #19
A business unit within your organization intends to deploy a new technology in a manner that places it in violation of existing information security standards. What immediate actio...
- Question #20
The PRIMARY objective of security awareness is to:
- Question #21
Which of the following is MOST likely to be discretionary?
- Question #22
Why is it vitally important that senior management endorse a security policy?
- Question #23
When would it be more desirable to develop a set of decentralized security policies and procedures within an enterprise environment?
- Question #24
What is the relationship between information protection and regulatory compliance?
- Question #25
Regulatory requirements typically force organizations to implement
- Question #26
When managing the security architecture for your company you must consider:
- Question #27
If your organization operates under a model of "assumption of breach", you should:
- Question #28
A method to transfer risk is to:
- Question #29
You have a system with 2 identified risks. You determine the probability of one risk occurring is higher than the
- Question #30
Ensuring that the actions of a set of people, applications and systems follow the organization's rules is BEST described as:
- Question #31
A security manager regualrly checks work areas after buisness hours for security violations; such as unsecured files or unattended computers with active sessions. This activity BES...
- Question #32
A Security Operations Centre (SOC) manager is informed that a database containing highly sensitive corporate strategy information is under attack. Information has been stolen and t...
- Question #33
A company wants to fill a Chief Information Security Officer position in the organization. They need to define and implement a more holistic security program. Which of the followin...
- Question #34
An organization licenses and uses personal information for business operations, and a server containing that information has been compromised. What kind of law would require notify...
- Question #35
An organization's firewall technology needs replaced. A specific technology has been selected that is less costly than others and lacking in some important capabilities. The securi...
- Question #36
An organization has defined a set of standard security controls. This organization has also defined the circumstances and conditions in which they must be applied. What is the NEXT...
- Question #37
A security manager has created a risk program. Which of the following is a critical part of ensuring the program is successful?
- Question #38
Which of the following international standards can be BEST used to define a Risk Management process in an organization?
- Question #39
An organization is looking for a framework to measure the efficiency and effectiveness of their Information Security Management System. Which of the following international standar...
- Question #40
A global retail company is creating a new compliance management process. Which of the following regulations is of MOST importance to be tracked and managed by this process?
- Question #41
A global retail organization is looking to implement a consistent Disaster Recovery and Business Continuity Process across all of its business units. Which of the following standar...
- Question #42
A global health insurance company is concerned about protecting confidential information. Which of the following is of MOST concern to this organization?
- Question #43
In which of the following cases, would an organization be more prone to risk acceptance vs. risk mitigation?
- Question #44
The exposure factor of a threat to your organization is defined by?
- Question #45
Risk is defined as:
- Question #46
What two methods are used to assess risk impact?
- Question #47
According to ISO 27001, of the steps for establishing an Information Security Governance program listed below, which comes first?
- Question #48
You have recently drafted a revised information security policy. From whom should you seek endorsement in order to have the GREATEST chance for adoption and implementation througho...
- Question #49
The success of the Chief Information Security Officer is MOST dependent upon:
- Question #50
An organization information security policy serves to