712-50 Exam Questions
505 real 712-50 exam questions with expert-verified answers and explanations. Page 4 of 11.
- Question #151
A department within your company has proposed a third party vendor solution to address an urgent, critical business need. As the CISO you have been asked to accelerate screening of...
- Question #152
Which business stakeholder is accountable for the integrity of a new information system?
- Question #153
The security team has investigated the theft/loss of several unencrypted laptop computers containing sensitive corporate information. To prevent the loss of any additional corporat...
- Question #154
A person in your security team calls you at night and informs you that one of your web applications is potentially under attack from a cross-site scripting vulnerability. What do y...
- Question #155
Knowing the potential financial loss an organization is willing to suffer if a system fails is a determination of which of the following?
- Question #156
A CISO decides to analyze the IT infrastructure to ensure security solutions adhere to the concepts of how hardware and software is implemented and managed within the organization....
- Question #157
Information Security is often considered an excessive, after-the-fact cost when a project or initiative is completed. What can be done to ensure that security is addressed cost eff...
- Question #158
The organization does not have the time to remediate the vulnerability; however it is critical to release the application. Which of the following needs to be further evaluated to h...
- Question #159
The company decides to release the application without remediating the high-risk vulnerabilities. Which of the following is the MOST likely reason for the company to release the ap...
- Question #160
This occurs when the quantity or quality of project deliverables is expanded from the original project plan.
- Question #161
Which of the following is considered a project versus a managed process?
- Question #162
What is the name of a formal statement that defines the strategy, approach, or expectations related to specific concerns within an organization?
- Question #163
When considering using a vendor to help support your security devices remotely, what is the BEST choice for allowing access?
- Question #164
Which of the following functions implements and oversees the use of controls to reduce risk when creating an information security program?
- Question #165
Which of the following is the BEST indicator of a successful project?
- Question #166
Risk appetite is typically determined by which of the following organizational functions?
- Question #167
An international organization is planning a project to implement encryption technologies to protect company confidential information. This organization has data centers on three co...
- Question #168
Which of the following is a major benefit of applying risk levels?
- Question #169
The Security Operations Center (SOC) just purchased a new intrusion prevention system (IPS) that needs to be deployed in-line for best defense. The IT group is concerned about putt...
- Question #170
Which of the following best summarizes the primary goal of a security program?
- Question #171
Which of the following represents the BEST method of ensuring security program alignment to business needs?
- Question #172
Acme Inc. has engaged a third party vendor to provide 99.999% up-time for their online web presence and had them contractually agree to this service level agreement. What type of r...
- Question #173
How often should the Statements of Standards for Attestation Engagements-16 (SSAE16)/International Standard on Assurance Engagements 3402 (ISAE3402) report of your vendors be revie...
- Question #174
An application vulnerability assessment has identified a security flaw in an application. This is a flaw that was previously identified and remediated on a prior release of the app...
- Question #175
Which of the following is MOST beneficial in determining an appropriate balance between uncontrolled innovation and excessive caution in an organization?
- Question #176
A recommended method to document the respective roles of groups and individuals for a given process is to:
- Question #177
Which of the following can the company implement in order to avoid this type of security issue in the future?
- Question #178
What oversight should the information security team have in the change management process for application security?
- Question #179
When should IT security project management be outsourced?
- Question #180
A newly appointed security officer finds data leakage software licenses that had never been used. The officer decides to implement a project to ensure it gets installed, but the pr...
- Question #181
Which of the following functions evaluates patches used to close software vulnerabilities of new systems to assure compliance with policy when implementing an information security...
- Question #182
A system was hardened at the Operating System level and placed into the production environment. Months later an audit was performed and it identified insecure configuration differe...
- Question #183
Which of the following will be MOST helpful for getting an Information Security project that is behind schedule back on schedule?
- Question #184
Which of the following is the MOST important component of any change management process?
- Question #185
How often should the SSAE16 report of your vendors be reviewed?
- Question #186
An example of professional unethical behavior is:
- Question #187
When is an application security development project complete?
- Question #188
When selecting a security solution with reoccurring maintenance costs after the first year (choose the BEST answer):
- Question #189
As the CISO for your company you are accountable for the protection of information resources commensurate with:
- Question #190
You manage a newly created Security Operations Center (SOC), your team is being inundated with security alerts and don't know what to do. What is the BEST approach to handle this s...
- Question #191
A CISO implements smart cards for credential management, and as a result has reduced costs associated with help desk operations supporting password resets. This demonstrates which...
- Question #192
A CISO has recently joined an organization with a poorly implemented security program. The desire is to base the security program on a risk management approach. Which of the follow...
- Question #193
To get an Information Security project back on schedule, which of the following will provide the MOST help?
- Question #194
Which of the following functions evaluates risk present in IT initiatives and/or systems when implementing an information security program?
- Question #195
Which of the following is critical in creating a security program aligned with an organization's goals?
- Question #196
Which of the following represents the BEST method for obtaining business unit acceptance of security controls within an organization?
- Question #197
You are having a penetration test done on your company network and the leader of the team says they discovered all the network devices because no one had changed the Simple Network...
- Question #198
The process of identifying and classifying assets is typically included in the
- Question #199
As a CISO you need to understand the steps that are used to perform an attack against a network. Put each step into the correct order. 1.Covering tracks 2.Scanning and enumeration...
- Question #200
Your organization provides open guest wireless access with no captive portals. What can you do to assist with law enforcement investigations if one of your guests is suspected of c...