512-50 Exam Questions
402 real 512-50 exam questions with expert-verified answers and explanations. Page 4 of 9.
- Question #151
When you develop your audit remediation plan what is the MOST important criteria?
- Question #152
Control Objectives for Information and Related Technology (COBIT) is which of the following?
- Question #153
A Chief Information Security Officer received a list of high, medium, and low impact audit findings. Which of the following represents the BEST course of action?
- Question #154
Which of the following represents the BEST reason for an organization to use the Control Objectives for Information and Related Technology (COBIT) as an Information Technology (IT)...
- Question #155
You are the Chief Information Security Officer of a large, multinational bank and you suspect there is a flaw in a two factor authentication token management process. Which of the...
- Question #156
Who is responsible for verifying that audit directives are implemented?
- Question #157
A person in your security team calls you at night and informs you that one of your web applications is potentially under attack from a cross-site scripting vulnerability. What do y...
- Question #158
An international organization is planning a project to implement encryption technologies to protect company confidential information. This organization has data centers on three co...
- Question #159
A system was hardened at the Operating System level and placed into the production environment. Months later an audit was performed and it identified insecure configuration differe...
- Question #160
Which of the following are not stakeholders of IT security projects?
- Question #161
The ultimate goal of an IT security projects is:
- Question #162
When managing the critical path of an IT security project, which of the following is MOST important?
- Question #163
When is an application security development project complete?
- Question #164
When should IT security project management be outsourced?
- Question #165
Which business stakeholder is accountable for the integrity of a new information system?
- Question #166
As the CISO for your company you are accountable for the protection of information resources commensurate with:
- Question #167
A stakeholder is a person or group:
- Question #168
Your company has a "no right to privacy" notice on all logon screens for your information systems and users sign an Acceptable Use Policy informing them of this condition. A peer g...
- Question #169
Acme Inc. has engaged a third party vendor to provide 99.999% up-time for their online web presence and had them contractually agree to this service level agreement. What type of r...
- Question #170
The security team has investigated the theft/loss of several unencrypted laptop computers containing sensitive corporate information. To prevent the loss of any additional corporat...
- Question #171
When gathering security requirements for an automated business process improvement program, which of the following is MOST important?
- Question #172
When selecting a security solution with reoccurring maintenance costs after the first year (choose the BEST answer):
- Question #173
Which of the following information may be found in table top exercises for incident response?
- Question #174
Your incident response plan should include which of the following?
- Question #175
You currently cannot provide for 24/7 coverage of your security monitoring and incident response duties and your company is resistant to the idea of adding more full-time employees...
- Question #176
To get an Information Security project back on schedule, which of the following will provide the MOST help?
- Question #177
How often should the Statements of Standards for Attestation Engagements-16 (SSAE16)/International Standard on Assurance Engagements 3402 (ISAE3402) report of your vendors be revie...
- Question #178
Information Security is often considered an excessive, after-the-fact cost when a project or initiative is completed. What can be done to ensure that security is addressed cost eff...
- Question #179
An application vulnerability assessment has identified a security flaw in an application. This is a flaw that was previously identified and remediated on a prior release of the app...
- Question #180
Which of the following is the MOST important component of any change management process?
- Question #181
Which of the following methods are used to define contractual obligations that force a vendor to meet customer expectations?
- Question #182
The company decides to release the application without remediating the high-risk vulnerabilities. Which of the following is the MOST likely reason for the company to release the ap...
- Question #183
The organization does not have the time to remediate the vulnerability; however it is critical to release the application. Which of the following needs to be further evaluated to h...
- Question #184
Which of the following can the company implement in order to avoid this type of security issue in the future?
- Question #185
Which of the following is considered a project versus a managed process?
- Question #186
Which of the following is the BEST indicator of a successful project?
- Question #187
Which of the following methodologies references the recommended industry standard that Information security project managers should follow?
- Question #188
This occurs when the quantity or quality of project deliverables is expanded from the original project plan.
- Question #189
Which of the following is considered one of the most frequent failures in project management?
- Question #190
When considering using a vendor to help support your security devices remotely, what is the BEST choice for allowing access?
- Question #191
When entering into a third party vendor agreement for security services, at what point in the process is it BEST to understand and validate the security posture and compliance leve...
- Question #192
When operating under severe budget constraints a CISO will have to be creative to maintain a strong security organization. Which example below is the MOST creative way to maintain...
- Question #193
The Security Operations Center (SOC) just purchased a new intrusion prevention system (IPS) that needs to be deployed in-line for best defense. The IT group is concerned about putt...
- Question #194
What oversight should the information security team have in the change management process for application security?
- Question #195
In order for a CISO to have true situational awareness there is a need to deploy technology that can give a real-time view of security events across the enterprise. Which tool sele...
- Question #196
You manage a newly created Security Operations Center (SOC), your team is being inundated with security alerts and don't know what to do. What is the BEST approach to handle this s...
- Question #197
An example of professional unethical behavior is:
- Question #198
A department within your company has proposed a third party vendor solution to address an urgent, critical business need. As the CISO you have been asked to accelerate screening of...
- Question #199
A severe security threat has been detected on your corporate network. As CISO you quickly assemble key members of the Information Technology team and business operations to determi...
- Question #200
A recommended method to document the respective roles of groups and individuals for a given process is to: