712-50 Exam Questions
505 real 712-50 exam questions with expert-verified answers and explanations. Page 1 of 11.
- Question #1
Which of the following intellectual Property components is focused on maintaining brand recognition?
- Question #2
Which of the following provides an audit framework?
- Question #3
The establishment of a formal risk management framework and system authorization program is essential. The LAST step of the system authorization process is:
- Question #4
A business unit within your organization intends to deploy a new technology in a manner that places it in violation of existing information security standards. What immediate actio...
- Question #5
An organization licenses and uses personal information for business operations, and a server containing that information has been compromised. What kind of law would require notify...
- Question #6
What is the definition of Risk in Information Security?
- Question #7
Which of the following is used to establish and maintain a framework to provide assurance that information security strategies are aligned with organizational objectives?
- Question #8
When managing an Information Security Program, which of the following is of MOST importance in order to influence the culture of an organization?
- Question #9
When dealing with a risk management process, asset classification is important because it will impact the overall:
- Question #10
When managing the security architecture for your company you must consider:
- Question #11
If your organization operates under a model of "assumption of breach", you should:
- Question #12
Information security policies should be reviewed:
- Question #13
Payment Card Industry (PCI) compliance requirements are based on what criteria?
- Question #14
What role should the CISO play in properly scoping a PCI environment?
- Question #15
From an information security perspective, information that no longer supports the main purpose of the business should be:
- Question #16
You have a system with 2 identified risks. You determine the probability of one risk occurring is higher than the
- Question #17
What is the SECOND step to creating a risk management methodology according to the National Institute of Standards and Technology (NIST) SP 800-30 standard?
- Question #18
In accordance with best practices and international standards, how often is security awareness training provided to employees of an organization?
- Question #19
What two methods are used to assess risk impact?
- Question #20
When would it be more desirable to develop a set of decentralized security policies and procedures within an enterprise environment?
- Question #21
Which of the following is considered the MOST effective tool against social engineering?
- Question #22
Quantitative Risk Assessments have the following advantages over qualitative risk assessments:
- Question #23
The FIRST step in establishing a security governance program is to?
- Question #24
What is the first thing that needs to be completed in order to create a security program for your organization?
- Question #25
An organization's Information Security Policy is of MOST importance because
- Question #26
Which of the following should be determined while defining risk management strategies?
- Question #27
Which of the following is a MAJOR consideration when an organization retains sensitive customer data and uses this data to better target the organization's products and services?
- Question #28
Which of the following is a detective control?
- Question #29
Which of the following lists are valid data-gathering activities associated with a risk assessment?
- Question #30
Developing effective security controls is a balance between:
- Question #31
The alerting, monitoring and life-cycle management of security related events is typically handled by the
- Question #32
When an organization claims it is secure because it is PCI-DSS certified, what is a good first question to ask towards assessing the effectiveness of their security program?
- Question #33
According to ISO 27001, of the steps for establishing an Information Security Governance program listed below, which comes first?
- Question #34
What is the MAIN reason for conflicts between Information Technology and Information Security programs?
- Question #35
An organization has defined a set of standard security controls. This organization has also defined the circumstances and conditions in which they must be applied. What is the NEXT...
- Question #36
The PRIMARY objective for information security program development should be:
- Question #37
Which of the following is a weakness of an asset or group of assets that can be exploited by one or more threats?
- Question #38
A global retail organization is looking to implement a consistent Disaster Recovery and Business Continuity Process across all of its business units. Which of the following standar...
- Question #39
A security officer wants to implement a vulnerability scanning program. The officer is uncertain of the state of vulnerability resiliency within the organization's large IT infrast...
- Question #40
What is the main purpose of the Incident Response Team?
- Question #41
In which of the following cases, would an organization be more prone to risk acceptance vs. risk mitigation?
- Question #42
When dealing with Security Incident Response procedures, which of the following steps come FIRST when reacting to an incident?
- Question #43
What is the relationship between information protection and regulatory compliance?
- Question #44
An organization's firewall technology needs replaced. A specific technology has been selected that is less costly than others and lacking in some important capabilities. The securi...
- Question #45
A security manager regualrly checks work areas after buisness hours for security violations; such as unsecured files or unattended computers with active sessions. This activity BES...
- Question #46
Which of the following is a benefit of information security governance?
- Question #47
The single most important consideration to make when developing your security program, policies, and processes is:
- Question #48
The Information Security Management program MUST protect:
- Question #49
A global health insurance company is concerned about protecting confidential information. Which of the following is of MOST concern to this organization?
- Question #50
Who is responsible for securing networks during a security incident?