712-50 Exam Questions
505 real 712-50 exam questions with expert-verified answers and explanations. Page 10 of 11.
- Question #451
What are the common data hiding techniques used by criminals?
- Question #452
When managing a project, the MOST important activity in managing the expectations of stakeholders is:
- Question #453
What is an approach to estimating the strengths and weaknesses of alternatives used to determine options, which provide the BEST approach to achieving benefits while preserving sav...
- Question #454
An organization has decided to develop an in-house BCM capability. The organization has determined it is best to follow a BCM standard published by the International Organization f...
- Question #455
From the CISO's perspective in looking at financial statements, the statement of retained earnings of an organization:
- Question #456
Devising controls for information security is a balance between?
- Question #457
Which of the following would not be considered an essential component of the strategic planning process?
- Question #458
An organization wants to purchase a turnkey inventory management system consisting of hardware and software. The organization wants to keep the price low, but its most important cr...
- Question #459
A security analyst is reviewing the security logs of a web server for indicators of compromise. Which of the following control functionalities is this an example of?
- Question #460
The CISO is writing an organization security policy. This is an example of which of the following control types?
- Question #461
An e-commerce site that accepts online payment is expanding and hires a CISO to ensure that the organization is complying with industry regulations and standards. Which of the foll...
- Question #462
Which of the following best describes the critical path in project management?
- Question #463
A disgruntled employee breaks into the organization and steals critical data after finding out he will be laid off due to downsizing. This is an example of what type of physical se...
- Question #464
NIST SP 800-53 outlines management, operational, and technical classes. Which of the following NIST control families is an example of a management control class?
- Question #465
A publicly traded company collects cardholder data in the course of business operations. The organization's CEO recognizes the importance of information security and hires a CISO....
- Question #466
Of the methods listed, what is the best countermeasure against social engineering attacks?
- Question #467
Securing facilities with Faraday cages or applying TEMPEST standards prevents the ability to monitor which of the following?
- Question #468
What is the primary difference between Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS)?
- Question #469
Which security technologies are MOST critical to implementing a zero trust model?
- Question #470
What is the estimate of all direct and indirect costs associated with an asset or acquisition over its entire life cycle?
- Question #471
What is generally the FIRST step in Information Security program development?
- Question #472
If a CISO wants to understand the liabilities of the company, she will refer to the:
- Question #473
What standard provides a comprehensive framework for information security risk management within organizations?
- Question #474
What is the THIRD state of the Tuchman Stages of Group Development?
- Question #475
Which of the following is an example of risk transference?
- Question #476
What is the THIRD state of the Tuckman Stages of Group Development?
- Question #477
Which of the following is the MOST important to share with an Information Security Steering Committee:
- Question #478
Which of the following provides the BEST approach to achieving positive outcomes while preserving savings?
- Question #479
The alerting, monitoring, and lifecycle management of security-related events are typically managed by the:
- Question #480
Which control is used to discourage the exploitation of a vulnerability or system?
- Question #481
Which security technologies are MOST critical to implementing a zero trust model?
- Question #482
The governing body that defines best practices for the collection of digital evidence is the:
- Question #483
Which of the following areas are beyond the duties of the CISO?
- Question #484
Which of the following is NOT an approach for ethical decision making?
- Question #485
What is a key goal of information security?
- Question #486
What standard would you use to help determine key performance indicators?
- Question #487
The Health Insurance Portability and Accountability Act (HIPAA) requires an agreement between Cloud Service Providers (CCSP) and the covered entity. Based on HIPAA. which document...
- Question #488
If a CISO wants to understand the liabilities of the company, she will refer to the:
- Question #489
What are the four groups that are critical to the success of evaluating and approving contracts during the negotiation phase?
- Question #490
What is the MAIN responsibility of the purple security testing team?
- Question #491
When gathering security requirements for an automated business process improvement program, which of the following is MOST important?
- Question #492
Which of the following refers to the quantity or quality of project deliverables expanding from the original project plan?
- Question #493
Effective information security management programs require the active involvement of_________
- Question #494
Which of the following is the MOST effective way to secure the physical hardware hosts in a virtualized environment?
- Question #495
What is defined as the friction or opposition resulting from actual or perceived differences or incompatibilities?
- Question #496
What is an example of a key performance indicator for cybersecurity?
- Question #497
Which of the following is an example of risk transference?
- Question #498
To reduce the threat of spear phishing, which of the following is the MOST critical security control to implement?
- Question #499
What Enterprise Architecture Framework is business-centric and is composed of eight phases?
- Question #500
Which publication serves as a resource of enterprise security-based standards and BEST practices?