712-50 Exam Questions
505 real 712-50 exam questions with expert-verified answers and explanations. Page 1 of 11.
- Question #1Governance (Policy, Legal & Compliance)
Which of the following intellectual Property components is focused on maintaining brand recognition?
Intellectual PropertyTrademarkBrand ProtectionLegal Compliance - Question #2
Which of the following provides an audit framework?
- Question #3
The establishment of a formal risk management framework and system authorization program is essential. The LAST step of the system authorization process is:
- Question #4
A business unit within your organization intends to deploy a new technology in a manner that places it in violation of existing information security standards. What immediate actio...
- Question #5
An organization licenses and uses personal information for business operations, and a server containing that information has been compromised. What kind of law would require notify...
- Question #6
What is the definition of Risk in Information Security?
- Question #7
Which of the following is used to establish and maintain a framework to provide assurance that information security strategies are aligned with organizational objectives?
- Question #8Security Program Management & Operations
When managing an Information Security Program, which of the following is of MOST importance in order to influence the culture of an organization?
security program managementorganizational culturesecurity-business alignmentgovernance - Question #9Cisco SMB Security Solutions
When dealing with a risk management process, asset classification is important because it will impact the overall:
risk managementasset classificationrisk treatmentinformation security - Question #10
When managing the security architecture for your company you must consider:
- Question #11Cisco SMB Security Solutions
If your organization operates under a model of "assumption of breach", you should:
assumption of breachrisk managementasset prioritizationsecurity strategy - Question #12
Information security policies should be reviewed:
- Question #13
Payment Card Industry (PCI) compliance requirements are based on what criteria?
- Question #14
What role should the CISO play in properly scoping a PCI environment?
- Question #15Governance (Policy, Legal & Compliance)
From an information security perspective, information that no longer supports the main purpose of the business should be:
data retention policydata lifecycle managementinformation governancecompliance - Question #16IS Management Controls and Auditing Management
You have a system with 2 identified risks. You determine the probability of one risk occurring is higher than the
risk assessmentprobability analysisrisk comparisonlikelihood evaluation - Question #17Security Program Management & Operations
What is the SECOND step to creating a risk management methodology according to the National Institute of Standards and Technology (NIST) SP 800-30 standard?
NIST SP 800-30Risk AssessmentRisk Management MethodologyRisk Framework - Question #18Governance (Policy, Legal & Compliance)
In accordance with best practices and international standards, how often is security awareness training provided to employees of an organization?
security awareness trainingcompliance standardsannual trainingemployee training - Question #19IS Management Controls and Auditing Management
What two methods are used to assess risk impact?
Risk AssessmentQuantitative RiskQualitative RiskRisk Impact - Question #20Governance (Policy, Legal & Compliance)
When would it be more desirable to develop a set of decentralized security policies and procedures within an enterprise environment?
decentralized governanceorganizational structuresecurity policiesenterprise risk management - Question #21Cisco SMB Security Solutions
Which of the following is considered the MOST effective tool against social engineering?
social engineeringsecurity awarenessanti-phishinghuman factor security - Question #22Information Security Core Competencies
Quantitative Risk Assessments have the following advantages over qualitative risk assessments:
Quantitative Risk AssessmentRisk MethodologiesRisk QuantificationObjective Analysis - Question #23
The FIRST step in establishing a security governance program is to?
- Question #24
What is the first thing that needs to be completed in order to create a security program for your organization?
- Question #25Governance (Policy, Legal & Compliance)
An organization's Information Security Policy is of MOST importance because
information security policymanagement commitmentgovernancerisk framework - Question #26
Which of the following should be determined while defining risk management strategies?
- Question #27
Which of the following is a MAJOR consideration when an organization retains sensitive customer data and uses this data to better target the organization's products and services?
- Question #28IS Management Controls and Auditing Management
Which of the following is a detective control?
detective controlsaudit trailcontrol typesincident detection - Question #29IS Management Controls and Auditing Management
Which of the following lists are valid data-gathering activities associated with a risk assessment?
Risk AssessmentThreat IdentificationVulnerability AnalysisControl Analysis - Question #30IS Management Controls and Auditing Management
Developing effective security controls is a balance between:
Risk ManagementSecurity ControlsOperations ManagementControl Development - Question #31
The alerting, monitoring and life-cycle management of security related events is typically handled by the
- Question #32Governance (Policy, Legal & Compliance)
When an organization claims it is secure because it is PCI-DSS certified, what is a good first question to ask towards assessing the effectiveness of their security program?
PCI-DSS ComplianceCompliance ScopeSecurity AssessmentCertification Limitations - Question #33Governance (Policy, Legal & Compliance)
According to ISO 27001, of the steps for establishing an Information Security Governance program listed below, which comes first?
ISO 27001Information Security GovernanceInformation Security PolicyRisk Management - Question #34Governance (Policy, Legal & Compliance)
What is the MAIN reason for conflicts between Information Technology and Information Security programs?
IT/Security governance conflictSecurity controls as business inhibitorOrganizational alignmentSecurity vs operational speed - Question #35
An organization has defined a set of standard security controls. This organization has also defined the circumstances and conditions in which they must be applied. What is the NEXT...
- Question #36
The PRIMARY objective for information security program development should be:
- Question #37
Which of the following is a weakness of an asset or group of assets that can be exploited by one or more threats?
- Question #38Governance (Policy, Legal & Compliance)
A global retail organization is looking to implement a consistent Disaster Recovery and Business Continuity Process across all of its business units. Which of the following standar...
Business ContinuityDisaster RecoveryISO-22301Organizational Standards - Question #39Security Program Management & Operations
A security officer wants to implement a vulnerability scanning program. The officer is uncertain of the state of vulnerability resiliency within the organization's large IT infrast...
vulnerability scanningrepresentative samplingscan methodologyrisk assessment - Question #40Security Program Management & Operations
What is the main purpose of the Incident Response Team?
Incident ResponseDisaster RecoverySystem RestorationBusiness Continuity - Question #41Security Program Management & Operations
In which of the following cases, would an organization be more prone to risk acceptance vs. risk mitigation?
Risk AcceptanceRisk ToleranceRisk Response StrategiesRisk Management - Question #42Security Program Management & Operations
When dealing with Security Incident Response procedures, which of the following steps come FIRST when reacting to an incident?
Incident ResponseContainmentIncident LifecycleResponse Procedures - Question #43
What is the relationship between information protection and regulatory compliance?
- Question #44
An organization's firewall technology needs replaced. A specific technology has been selected that is less costly than others and lacking in some important capabilities. The securi...
- Question #45
A security manager regualrly checks work areas after buisness hours for security violations; such as unsecured files or unattended computers with active sessions. This activity BES...
- Question #46
Which of the following is a benefit of information security governance?
- Question #47
The single most important consideration to make when developing your security program, policies, and processes is:
- Question #48
The Information Security Management program MUST protect:
- Question #49Governance (Policy, Legal & Compliance)
A global health insurance company is concerned about protecting confidential information. Which of the following is of MOST concern to this organization?
patient data protectionhealthcare compliancedata privacy regulationsconfidential information - Question #50
Who is responsible for securing networks during a security incident?