712-50 Exam Questions
505 real 712-50 exam questions with expert-verified answers and explanations. Page 10 of 11.
- Question #451Information Security Core Competencies
What are the common data hiding techniques used by criminals?
data hidingsteganographyencryptiondigital forensics - Question #452Security Program Management & Operations
When managing a project, the MOST important activity in managing the expectations of stakeholders is:
stakeholder managementproject communicationexpectation managementproject management - Question #453Strategic Planning, Finance, Procurement, and Vendor Management
What is an approach to estimating the strengths and weaknesses of alternatives used to determine options, which provide the BEST approach to achieving benefits while preserving sav...
cost-benefit analysisfinancial decision makinginvestment evaluationalternatives analysis - Question #454
An organization has decided to develop an in-house BCM capability. The organization has determined it is best to follow a BCM standard published by the International Organization f...
- Question #455Strategic Planning, Finance, Procurement, and Vendor Management
From the CISO's perspective in looking at financial statements, the statement of retained earnings of an organization:
financial statementsretained earningssecurity budgetCISO financial literacy - Question #456
Devising controls for information security is a balance between?
- Question #457Strategic Planning, Finance, Procurement, and Vendor Management
Which of the following would not be considered an essential component of the strategic planning process?
Strategic Planning ProcessEssential ComponentsTeam CompositionPlanning Tools - Question #458
An organization wants to purchase a turnkey inventory management system consisting of hardware and software. The organization wants to keep the price low, but its most important cr...
- Question #459
A security analyst is reviewing the security logs of a web server for indicators of compromise. Which of the following control functionalities is this an example of?
- Question #460
The CISO is writing an organization security policy. This is an example of which of the following control types?
- Question #461
An e-commerce site that accepts online payment is expanding and hires a CISO to ensure that the organization is complying with industry regulations and standards. Which of the foll...
- Question #462Strategic Planning, Finance, Procurement, and Vendor Management
Which of the following best describes the critical path in project management?
Critical Path MethodProject SchedulingActivity DependenciesFloat/Slack Analysis - Question #463Information Security Core Competencies
A disgruntled employee breaks into the organization and steals critical data after finding out he will be laid off due to downsizing. This is an example of what type of physical se...
Physical Security ThreatsInsider ThreatsThreat ClassificationManmade Threats - Question #464
NIST SP 800-53 outlines management, operational, and technical classes. Which of the following NIST control families is an example of a management control class?
- Question #465
A publicly traded company collects cardholder data in the course of business operations. The organization's CEO recognizes the importance of information security and hires a CISO....
- Question #466
Of the methods listed, what is the best countermeasure against social engineering attacks?
- Question #467
Securing facilities with Faraday cages or applying TEMPEST standards prevents the ability to monitor which of the following?
- Question #468Information Security Core Competencies
What is the primary difference between Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS)?
IDS/IPSNetwork DefenseThreat DetectionPrevention Systems - Question #469
Which security technologies are MOST critical to implementing a zero trust model?
- Question #470Strategic Planning, Finance, Procurement, and Vendor Management
What is the estimate of all direct and indirect costs associated with an asset or acquisition over its entire life cycle?
Total Cost of OwnershipLife Cycle CostsCost EstimationProcurement - Question #471Security Program Management & Operations
What is generally the FIRST step in Information Security program development?
security program developmentassessment phaseprogram lifecycleinformation security - Question #472Strategic Planning, Finance, Procurement, and Vendor Management
If a CISO wants to understand the liabilities of the company, she will refer to the:
balance sheetfinancial statementsliabilitiesfinancial acumen - Question #473
What standard provides a comprehensive framework for information security risk management within organizations?
- Question #474Security Program Management & Operations
What is the THIRD state of the Tuchman Stages of Group Development?
Tuchman StagesGroup DevelopmentTeam DynamicsOrganizational Leadership - Question #475Strategic Planning, Finance, Procurement, and Vendor Management
Which of the following is an example of risk transference?
Risk TransferenceInsuranceRisk ManagementRisk Transfer - Question #476Security Program Management & Operations
What is the THIRD state of the Tuckman Stages of Group Development?
Tuckman modelteam development stagesgroup dynamicsorganizational behavior - Question #477Governance (Policy, Legal & Compliance)
Which of the following is the MOST important to share with an Information Security Steering Committee:
IS Steering CommitteeAudit ReportsCompliance ManagementGovernance Oversight - Question #478Strategic Planning, Finance, Procurement, and Vendor Management
Which of the following provides the BEST approach to achieving positive outcomes while preserving savings?
cost-benefit analysisfinancial toolsROIinvestment decisions - Question #479Security Program Management & Operations
The alerting, monitoring, and lifecycle management of security-related events are typically managed by the:
security monitoringevent lifecyclethreat managementvulnerability management - Question #480
Which control is used to discourage the exploitation of a vulnerability or system?
- Question #481
Which security technologies are MOST critical to implementing a zero trust model?
- Question #482
The governing body that defines best practices for the collection of digital evidence is the:
- Question #483
Which of the following areas are beyond the duties of the CISO?
- Question #484Governance (Policy, Legal & Compliance)
Which of the following is NOT an approach for ethical decision making?
Ethical decision-making frameworksRisk management vs ethicsGovernance principlesEthics compliance - Question #485Information Security Core Competencies
What is a key goal of information security?
Information Security GoalsRisk ManagementGovernanceRisk Mitigation - Question #486Security Program Management & Operations
What standard would you use to help determine key performance indicators?
NISTSP800-55Key Performance IndicatorsSecurity MetricsProgram Measurement - Question #487Governance (Policy, Legal & Compliance)
The Health Insurance Portability and Accountability Act (HIPAA) requires an agreement between Cloud Service Providers (CCSP) and the covered entity. Based on HIPAA. which document...
HIPAABusiness Associate AgreementCloud Provider ComplianceCovered Entity - Question #488
If a CISO wants to understand the liabilities of the company, she will refer to the:
- Question #489
What are the four groups that are critical to the success of evaluating and approving contracts during the negotiation phase?
- Question #490
What is the MAIN responsibility of the purple security testing team?
- Question #491Security Program Management & Operations
When gathering security requirements for an automated business process improvement program, which of the following is MOST important?
data classificationsecurity requirementsrisk assessmentcontrol framework - Question #492Strategic Planning, Finance, Procurement, and Vendor Management
Which of the following refers to the quantity or quality of project deliverables expanding from the original project plan?
Scope CreepProject DeliverablesScope ManagementProject Planning - Question #493
Effective information security management programs require the active involvement of_________
- Question #494IS Management Controls and Auditing Management
Which of the following is the MOST effective way to secure the physical hardware hosts in a virtualized environment?
Virtualization SecurityPhysical Host ControlsInfrastructure SecurityControl Implementation - Question #495Security Program Management & Operations
What is defined as the friction or opposition resulting from actual or perceived differences or incompatibilities?
organizational dynamicsconflict managementteam moraleemployee relations - Question #496Security Program Management & Operations
What is an example of a key performance indicator for cybersecurity?
KPI MetricsIncident TrackingSecurity Program ManagementPerformance Measurement - Question #497Strategic Planning, Finance, Procurement, and Vendor Management
Which of the following is an example of risk transference?
risk transferencerisk managementinsurancerisk strategies - Question #498IS Management Controls and Auditing Management
To reduce the threat of spear phishing, which of the following is the MOST critical security control to implement?
Spear phishingSecurity awareness and trainingSocial engineering defenseSecurity controls - Question #499Governance (Policy, Legal & Compliance)
What Enterprise Architecture Framework is business-centric and is composed of eight phases?
Enterprise Architecture FrameworkTOGAFArchitecture Development MethodBusiness-centric - Question #500
Which publication serves as a resource of enterprise security-based standards and BEST practices?