512-50 Exam Questions
402 real 512-50 exam questions with expert-verified answers and explanations. Page 6 of 9.
- Question #253
The ability to demand the implementation and management of security controls on third parties providing services to an organization is
- Question #254
Which of the following is considered the foundation for the Enterprise Information Security Architecture (EISA)?
- Question #255
The process to evaluate the technical and non-technical security controls of an IT system to validate that a given design and implementation meet a specific set of security require...
- Question #256
The process for management approval of the security certification process which states the risks and mitigation of such risks of a given IT system is called
- Question #257
Access Control lists (ACLs), Firewalls, and Intrusion Prevention Systems are examples of
- Question #258
File Integrity Monitoring (FIM) is considered a
- Question #259
A system is designed to dynamically block offending Internet IP-addresses from requesting services from a secure website. This type of control is considered
- Question #260
When dealing with risk, the information security practitioner may choose to:
- Question #261
Your company has limited resources to spend on security initiatives. The Chief Financial Officer asks you to prioritize the protection of information resources based on their value...
- Question #262
The total cost of security controls should:
- Question #263
Annual Loss Expectancy is derived from the function of which two factors?
- Question #264
The Annualized Loss Expectancy (Before) minus Annualized Loss Expectancy (After) minus Annual Safeguard Cost is the formula for determining:
- Question #265
Which of the following provides an independent assessment of a vendor's internal security controls and overall posture?
- Question #266
The rate of change in technology increases the importance of:
- Question #267
As the CISO you need to write the IT security strategic plan. Which of the following is the MOST important to review before you start writing the plan?
- Question #268
Involvement of senior management is MOST important in the development of:
- Question #269
The newly appointed CISO of an organization is reviewing the IT security strategic plan. Which of the following is the MOST important component of the strategic plan?
- Question #270
John is the project manager for a large project in his organization. A new change request has been proposed that will affect several areas of the project. One area of the project c...
- Question #271
When updating the security strategic planning document what two items must be included?
- Question #272
Acceptable levels of information security risk tolerance in an organization should be determined by?
- Question #273
The formal certification and accreditation process has four primary steps, what are they?
- Question #274
Human resource planning for security professionals in your organization is a:
- Question #275
What are the primary reasons for the development of a business case for a security project?
- Question #276
When analyzing and forecasting a capital expense budget what are not included?
- Question #277
When analyzing and forecasting an operating expense budget what are not included?
- Question #278
What is the primary reason for performing a return on investment analysis?
- Question #279
What is the primary reason for performing vendor management?
- Question #280
What is the BEST reason for having a formal request for proposal process?
- Question #281
When creating contractual agreements and procurement processes why should security requirements be included?
- Question #282
Scenario: Your program is developed around minimizing risk to information by focusing on people, technology, and operations. You have decided to deal with risk to information from...
- Question #283
Scenario: Your program is developed around minimizing risk to information by focusing on people, technology, and operations. An effective way to evaluate the effectiveness of an in...
- Question #284
Scenario: Most industries require compliance with multiple government regulations and/or industry standards to meet data protection and privacy mandates. What is one proven method...
- Question #285
Scenario: Most industries require compliance with multiple government regulations and/or industry standards to meet data protection and privacy mandates. When multiple regulations...
- Question #286
Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined sec...
- Question #287
Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined sec...
- Question #288
Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organizat...
- Question #289
Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organizat...
- Question #290
Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organizat...
- Question #291
Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organizat...
- Question #292
SCENARIO: Critical servers show signs of erratic behavior within your organization's intranet. Initial information indicates the systems are under attack from an outside entity. As...
- Question #293
SCENARIO: Critical servers show signs of erratic behavior within your organization's intranet. Initial information indicates the systems are under attack from an outside entity. As...
- Question #294
SCENARIO: Critical servers show signs of erratic behavior within your organization's intranet. Initial information indicates the systems are under attack from an outside entity. As...
- Question #295
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used a...
- Question #296
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used a...
- Question #297
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used a...
- Question #298
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used a...
- Question #299
Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate c...
- Question #300
Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate c...
- Question #301
Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate c...
- Question #302
Scenario: Your organization employs single sign-on (user name and password only) as a convenience to your employees to access organizational systems and data. Permission to individ...