nerdexam
EC-Council

512-50 · Question #306

Scenario: You are the CISO and are required to brief the C-level executive team on your information security audit for the year. During your review of the audit findings you discover that many of…

The correct answer is A. Business Impact Analysis. See the full explanation below for the reasoning.

Question

Scenario: You are the CISO and are required to brief the C-level executive team on your information security audit for the year. During your review of the audit findings you discover that many of the controls that were put in place the previous year to correct some of the findings are not performing as needed. You have thirty days until the briefing. To formulate a remediation plan for the non-performing controls what other document do you need to review before adjusting the controls?

Options

  • ABusiness Impact Analysis
  • BBusiness Continuity plan
  • CSecurity roadmap
  • DAnnual report to shareholders

How the community answered

(52 responses)
  • A
    85% (44)
  • B
    2% (1)
  • C
    6% (3)
  • D
    8% (4)

Community Discussion

No community discussion yet for this question.

Full 512-50 Practice