712-50 Exam Questions
505 real 712-50 exam questions with expert-verified answers and explanations. Page 3 of 11.
- Question #101
In MOST organizations which group periodically reviews network intrusion detection system logs for all systems as part of their daily tasks?
- Question #102IS Management Controls and Auditing Management
The CIO of an organization has decided to assign the responsibility of internal IT audit to the IT team. This is consider a bad practice MAINLY because
Audit IndependenceConflict of InterestSegregation of DutiesInternal Controls - Question #103
When you develop your audit remediation plan what is the MOST important criteria?
- Question #104Governance (Policy, Legal & Compliance)
Which of the following represents the BEST reason for an organization to use the Control Objectives for Information and Related Technology (COBIT) as an Information Technology (IT)...
COBIT frameworkIT governanceCompliance and auditingControl objectives - Question #105IS Management Controls and Auditing Management
Which of the following organizations is typically in charge of validating the implementation and effectiveness of security controls?
Control ValidationAudit FunctionsOrganizational RolesGovernance - Question #106IS Management Controls and Auditing Management
Dataflow diagrams are used by IT auditors to:
Dataflow DiagramsIT AuditingSystem AnalysisData Visualization - Question #107Security Program Management & Operations
Which International Organization for Standardization (ISO) below BEST describes the performance of risk management, and includes a five-stage risk management methodology?
ISO 27005Risk ManagementInformation SecurityFive-stage methodology - Question #108
Many times a CISO may have to speak to the Board of Directors (BOD) about their cyber security posture. What would be the BEST choice of security metrics to present to the BOD?
- Question #109
Which of the following activities results in change requests?
- Question #110
Providing oversight of a comprehensive information security program for the entire organization is the primary responsibility of which group under the InfoSec governance framework?
- Question #111IS Management Controls and Auditing Management
An audit was conducted and many critical applications were found to have no disaster recovery plans in place. You conduct a Business Impact Analysis (BIA) to determine impact to th...
Business Impact AnalysisDisaster Recovery PlanningRecovery Plan DevelopmentAudit Response - Question #112Governance (Policy, Legal & Compliance)
When working in the Payment Card Industry (PCI), how often should security logs be review to comply with the standards?
PCI DSSLog ManagementCompliance RequirementsSecurity Monitoring - Question #113Information Security Core Competencies
Creating a secondary authentication process for network access would be an example of?
Multi-factor authenticationLayered securityDefense in depthAccess control - Question #114Governance (Policy, Legal & Compliance)
Which of the following BEST describes an international standard framework that is based on the security model Information Technology--Code of Practice for Information Security Mana...
ISO 27001ISO 27002Information Security FrameworkSecurity Standards - Question #115IS Management Controls and Auditing Management
The effectiveness of an audit is measured by?
audit effectivenessbusiness alignmentrisk managementaudit recommendations - Question #116IS Management Controls and Auditing Management
An IT auditor has recently discovered that because of a shortage of skilled operations personnel, the security administrator has agreed to work one late night shift a week as the s...
Segregation of DutiesInternal ControlsAudit IndependenceRisk Reporting - Question #117IS Management Controls and Auditing Management
With respect to the audit management process, management response serves what function?
Audit ManagementManagement ResponseFinding RemediationResource Allocation - Question #118
Creating good security metrics is essential for a CISO. What would be the BEST sources for creating security metrics for baseline defenses coverage?
- Question #119
A recent audit has identified a few control exceptions and is recommending the implementation of technology and processes to address the finding. Which of the following is the MOST...
- Question #120IS Management Controls and Auditing Management
A new CISO just started with a company and on the CISO's desk is the last complete Information Security Management audit report. The audit report is over two years old. After readi...
audit follow-upaudit recommendationscompliance managementCISO responsibilities - Question #121IS Management Controls and Auditing Management
The risk found after a control has been fully implemented is called:
Residual RiskRisk ManagementControl ImplementationRisk Assessment - Question #122IS Management Controls and Auditing Management
Step-by-step procedures to regain normalcy in the event of a major earthquake is PRIMARILY covered by which of the following plans?
Disaster RecoveryBusiness Continuity PlanningIncident ManagementRisk Mitigation - Question #123IS Management Controls and Auditing Management
Which of the following best represents a calculation for Annual Loss Expectancy (ALE)?
ALE calculationrisk quantificationloss expectancyannual rate of occurrence - Question #124
Which of the following is the MOST effective way to measure the effectiveness of security controls on a perimeter network?
- Question #125
To have accurate and effective information security policies how often should the CISO review the organization policies?
- Question #126Security Program Management & Operations
The effectiveness of social engineering penetration testing using phishing can be used as a Key Performance Indicator (KPI) for the effectiveness of an organization's
Social Engineering TestingPhishing AwarenessSecurity KPIsEmployee Training - Question #127
Which of the following activities must be completed BEFORE you can calculate risk?
- Question #128
Which of the following is a fundamental component of an audit record?
- Question #129Governance (Policy, Legal & Compliance)
Which of the following is considered to be an IT governance framework and a supporting toolset that allows for managers to bridge the gap between control requirements, technical is...
IT GovernanceCOBIT FrameworkControl FrameworksRisk Management - Question #130
The amount of risk an organization is willing to accept in pursuit of its mission is known as
- Question #131IS Management Controls and Auditing Management
Which of the following is the MOST important reason to measure the effectiveness of an Information Security Management System (ISMS)?
ISMS effectiveness measurementprogram assessmentcontinuous improvementcontrol evaluation - Question #132Governance (Policy, Legal & Compliance)
Which represents PROPER separation of duties in the corporate environment?
Separation of DutiesAccess ControlGovernanceRisk Management - Question #133
As a new CISO at a large healthcare company you are told that everyone has to badge in to get in the building. Below your office window you notice a door that is normally propped o...
- Question #134IS Management Controls and Auditing Management
During the course of a risk analysis your IT auditor identified threats and potential impacts. Next, your IT auditor should:
Risk AnalysisControls AssessmentAudit MethodologyRisk Management - Question #135IS Management Controls and Auditing Management
The implementation of anti-malware and anti-phishing controls on centralized email servers is an example of what type of security control?
Technical ControlsEmail SecurityMalware/Phishing DefenseControl Classification - Question #136IS Management Controls and Auditing Management
An organization has implemented a change management process for all changes to the IT production environment. This change management process follows best practices and is expected...
change managementavailability metricsunplanned outagesprocess effectiveness - Question #137
The remediation of a specific audit finding is deemed too expensive and will not be implemented. Which of the following is a TRUE statement?
- Question #138
The patching and monitoring of systems on a consistent schedule is required by?
- Question #139
The MOST common method to get an unbiased measurement of the effectiveness of an Information Security Management System (ISMS) is to
- Question #140
The mean time to patch, number of virus outbreaks prevented, and number of vulnerabilities mitigated are examples of what type of performance metrics?
- Question #141
Your company has a "no right to privacy" notice on all logon screens for your information systems and users sign an Acceptable Use Policy informing them of this condition. A peer g...
- Question #142Security Program Management & Operations
Which of the following is considered one of the most frequent failures in project management?
Project DeadlinesProject ManagementSchedule ManagementResource Planning - Question #143
You are the CISO of a commercial social media organization. The leadership wants to rapidly create new methods of sharing customer data through creative linkages with mobile device...
- Question #144
Which of the following information may be found in table top exercises for incident response?
- Question #145
When operating under severe budget constraints a CISO will have to be creative to maintain a strong security organization. Which example below is the MOST creative way to maintain...
- Question #146Strategic Planning, Finance, Procurement, and Vendor Management
Which of the following methods are used to define contractual obligations that force a vendor to meet customer expectations?
Service Level AgreementsVendor ManagementContractual ObligationsPerformance Standards - Question #147
When gathering security requirements for an automated business process improvement program, which of the following is MOST important?
- Question #148
Your incident response plan should include which of the following?
- Question #149
A CISO sees abnormally high volumes of exceptions to security requirements and constant pressure from business units to change security processes. Which of the following represents...
- Question #150
An organization has a stated requirement to block certain traffic on networks. The implementation of controls will disrupt a manufacturing process and cause unacceptable delays, re...