512-50 Exam Questions
402 real 512-50 exam questions with expert-verified answers and explanations. Page 3 of 9.
- Question #101
The patching and monitoring of systems on a consistent schedule is required by?
- Question #102
As the new CISO at the company you are reviewing the audit reporting process and notice that it includes only detailed technical diagrams. What else should be in the reporting proc...
- Question #103
As a new CISO at a large healthcare company you are told that everyone has to badge in to get in the building. Below your office window you notice a door that is normally propped o...
- Question #104
Assigning the role and responsibility of Information Assurance to a dedicated and independent security group is an example of:
- Question #105
The CIO of an organization has decided to assign the responsibility of internal IT audit to the IT team. This is consider a bad practice MAINLY because
- Question #106
The BEST organization to provide a comprehensive, independent and certifiable perspective on established security controls in an environment is
- Question #107
An organization has implemented a change management process for all changes to the IT production environment. This change management process follows best practices and is expected...
- Question #108
Which of the following is the MOST effective way to measure the effectiveness of security controls on a perimeter network?
- Question #109
Which of the following organizations is typically in charge of validating the implementation and effectiveness of security controls?
- Question #110
A recent audit has identified a few control exceptions and is recommending the implementation of technology and processes to address the finding. Which of the following is the MOST...
- Question #111
The remediation of a specific audit finding is deemed too expensive and will not be implemented. Which of the following is a TRUE statement?
- Question #112
A missing/ineffective security control is identified. Which of the following should be the NEXT step?
- Question #113
The risk found after a control has been fully implemented is called:
- Question #114
In MOST organizations which group periodically reviews network intrusion detection system logs for all systems as part of their daily tasks?
- Question #115
At which point should the identity access management team be notified of the termination of an employee?
- Question #116
To have accurate and effective information security policies how often should the CISO review the organization policies?
- Question #117
How often should an environment be monitored for cyber threats, risks, and exposures?
- Question #118
Which is the BEST solution to monitor, measure, and report changes to critical data in a system?
- Question #119
When working in the Payment Card Industry (PCI), how often should security logs be review to comply with the standards?
- Question #120
Which represents PROPER separation of duties in the corporate environment?
- Question #121
Creating good security metrics is essential for a CISO. What would be the BEST sources for creating security metrics for baseline defenses coverage?
- Question #122
Many times a CISO may have to speak to the Board of Directors (BOD) about their cyber security posture. What would be the BEST choice of security metrics to present to the BOD?
- Question #123
When a critical vulnerability has been discovered on production systems and needs to be fixed immediately, what is the BEST approach for a CISO to mitigate the vulnerability under...
- Question #124
An information security department is required to remediate system vulnerabilities when they are discovered. Please select the three primary remediation methods that can be used on...
- Question #125
When a CISO considers delaying or not remediating system vulnerabilities which of the following are MOST important to take into account?
- Question #126
The effectiveness of an audit is measured by?
- Question #127
A new CISO just started with a company and on the CISO's desk is the last complete Information Security Management audit report. The audit report is over two years old. After readi...
- Question #128
You have implemented the new controls. What is the next step?
- Question #129
An audit was conducted and many critical applications were found to have no disaster recovery plans in place. You conduct a Business Impact Analysis (BIA) to determine impact to th...
- Question #130
Which of the following is considered to be an IT governance framework and a supporting toolset that allows for managers to bridge the gap between control requirements, technical is...
- Question #131
Which of the following set of processes is considered to be one of the cornerstone cycles of the International Organization for Standardization (ISO) 27001 standard?
- Question #132
Which of the following best describes the purpose of the International Organization for Standardization (ISO) 27002 standard?
- Question #133
Providing oversight of a comprehensive information security program for the entire organization is the primary responsibility of which group under the InfoSec governance framework?
- Question #134
An employee successfully avoids becoming a victim of a sophisticated spear phishing attack due to knowledge gained through the corporate information security awareness program. Wha...
- Question #135
Which of the following illustrates an operational control process:
- Question #136
With respect to the audit management process, management response serves what function?
- Question #137
Which of the following are primary concerns for management with regard to assessing internal control objectives?
- Question #138
Which of the following are necessary to formulate responses to external audit findings?
- Question #139
The executive board has requested that the CISO of an organization define and Key Performance Indicators (KPI) to measure the effectiveness of the security awareness program provid...
- Question #140
Creating a secondary authentication process for network access would be an example of?
- Question #141
Which of the following activities is the MAIN purpose of the risk assessment process?
- Question #142
Which of the following activities must be completed BEFORE you can calculate risk?
- Question #143
Step-by-step procedures to regain normalcy in the event of a major earthquake is PRIMARILY covered by which of the following plans?
- Question #144
Which International Organization for Standardization (ISO) below BEST describes the performance of risk management, and includes a five-stage risk management methodology.
- Question #145
Which of the following BEST describes an international standard framework that is based on the security model Information Technology--Code of Practice for Information Security Mana...
- Question #146
Which of the following is the PRIMARY purpose of International Organization for Standardization (ISO) 27001?
- Question #147
The MOST common method to get an unbiased measurement of the effectiveness of an Information Security Management System (ISMS) is to
- Question #148
The effectiveness of social engineering penetration testing using phishing can be used as a Key Performance Indicator (KPI) for the effectiveness of an organization's
- Question #149
Which of the following is the MOST important reason to measure the effectiveness of an Information Security Management System (ISMS)?
- Question #150
The mean time to patch, number of virus outbreaks prevented, and number of vulnerabilities mitigated are examples of what type of performance metrics?