nerdexam
EC-Council

512-50 · Question #299

Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate controls. You…

The correct answer is D. Never. See the full explanation below for the reasoning.

Question

Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate controls. You assign work to your staff to create or adjust existing security controls to ensure they are adequate for risk mitigation needs. When adjusting the controls to mitigate the risks, how often should the CISO perform an audit to verify the controls?

Options

  • AAnnually
  • BSemi-annually
  • CQuarterly
  • DNever

How the community answered

(39 responses)
  • A
    15% (6)
  • B
    3% (1)
  • C
    8% (3)
  • D
    74% (29)

Community Discussion

No community discussion yet for this question.

Full 512-50 Practice