nerdexam
EC-Council

512-50 · Question #298

SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used as audit baselines…

The correct answer is A. Validate the effectiveness of applied controls. See the full explanation below for the reasoning.

Question

SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used as audit baselines. The audit report was presented to the CISO and a variety of high, medium and low rated gaps were identified. The CISO has implemented remediation activities. Which of the following is the MOST logical next step?

Options

  • AValidate the effectiveness of applied controls
  • BValidate security program resource requirements
  • CReport the audit findings and remediation status to business stake holders
  • DReview security procedures to determine if they need modified according to findings

How the community answered

(46 responses)
  • A
    83% (38)
  • B
    2% (1)
  • C
    4% (2)
  • D
    11% (5)

Community Discussion

No community discussion yet for this question.

Full 512-50 Practice