712-50 Exam Questions
505 real 712-50 exam questions with expert-verified answers and explanations. Page 6 of 11.
- Question #251
Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined sec...
- Question #252
A system is designed to dynamically block offending Internet IP-addresses from requesting services from a secure website. This type of control is considered
- Question #253
Which of the following is considered the foundation for the Enterprise Information Security Architecture (EISA)?
- Question #254
Which of the following provides an independent assessment of a vendor's internal security controls and overall posture?
- Question #255
Scenario: You are the CISO and are required to brief the C-level executive team on your information security audit for the year. During your review of the audit findings you discov...
- Question #256
Annual Loss Expectancy is derived from the function of which two factors?
- Question #257Security Program Management & Operations
SCENARIO: Critical servers show signs of erratic behavior within your organization's intranet. Initial information indicates the systems are under attack from an outside entity. As...
Incident ResponseForensic InvestigationEvidence PreservationIR Phases - Question #258Governance (Policy, Legal & Compliance)
The rate of change in technology increases the importance of:
change managementgovernanceprocess controlorganizational resilience - Question #259Strategic Planning, Finance, Procurement, and Vendor Management
John is the project manager for a large project in his organization. A new change request has been proposed that will affect several areas of the project. One area of the project c...
Vendor ManagementContract ManagementChange ManagementProcurement - Question #260Security Program Management & Operations
Scenario: As you begin to develop the program for your organization, you assess the corporate culture and determine that there is a pervasive opinion that the security program only...
Stakeholder engagementSecurity cultureChange managementProgram development - Question #261
What is the primary reason for performing vendor management?
- Question #262
Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate c...
- Question #263Security Program Management & Operations
Scenario: Your company has many encrypted telecommunications links for their world-wide operations. Physically distributing symmetric keys to all locations has proven to be adminis...
Key DistributionPKIHybrid CryptographyAsymmetric Encryption - Question #264Governance (Policy, Legal & Compliance)
Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organizat...
PCI DSS compliancepayment card securitycompliance standardscredit card fraud - Question #265
Human resource planning for security professionals in your organization is a:
- Question #266
You are just hired as the new CISO and are being briefed on all the Information Security projects that your section has on going. You discover that most projects are behind schedul...
- Question #267
When analyzing and forecasting an operating expense budget what are not included?
- Question #268
Scenario: The new CISO was informed of all the Information Security projects that the section has in progress. Two projects are over a year behind schedule and way over budget. Whi...
- Question #269
Your company has limited resources to spend on security initiatives. The Chief Financial Officer asks you to prioritize the protection of information resources based on their value...
- Question #270Strategic Planning, Finance, Procurement, and Vendor Management
Which of the following conditions would be the MOST probable reason for a security project to be rejected by the executive board of an organization?
NPV AnalysisFinancial MetricsProject JustificationCapital Investment - Question #271Governance (Policy, Legal & Compliance)
Scenario: Most industries require compliance with multiple government regulations and/or industry standards to meet data protection and privacy mandates. What is one proven method...
Compliance mappingRegulatory alignmentStandards crosswalkGovernance frameworks - Question #272
Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organizat...
- Question #273Governance (Policy, Legal & Compliance)
The formal certification and accreditation process has four primary steps, what are they?
Certification & AccreditationC&A ProcessSystem AuthorizationCompliance - Question #274
Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined sec...
- Question #275IS Management Controls and Auditing Management
Access Control lists (ACLs), Firewalls, and Intrusion Prevention Systems are examples of
Preventative ControlsNetwork SecurityFirewallsAccess Control - Question #276
Scenario: As you begin to develop the program for your organization, you assess the corporate culture and determine that there is a pervasive opinion that the security program only...
- Question #277
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used a...
- Question #278
The total cost of security controls should:
- Question #279
Scenario: Your corporate systems have been under constant probing and attack from foreign IP addresses for more than a week. Your security team and security infrastructure have per...
- Question #280
SCENARIO: A CISO has several two-factor authentication systems under review and selects the one that is most sufficient and least costly. The implementation project planning is com...
- Question #281
Scenario: Your organization employs single sign-on (user name and password only) as a convenience to your employees to access organizational systems and data. Permission to individ...
- Question #282
When analyzing and forecasting a capital expense budget what are not included?
- Question #283Information Security Core Competencies
One advantage of an application-level firewall is the ability to
Application-level firewallsLayer 7 filteringProtocol inspectionHTTP methods - Question #284
Which of the following is an advantage of utilizing security testing methodologies to conduct a security audit?
- Question #285Security Program Management & Operations
When dealing with risk, the information security practitioner may choose to:
Risk Response StrategiesRisk AcceptanceRisk ManagementSecurity Decision-Making - Question #286
SCENARIO: A CISO has several two-factor authentication systems under review and selects the one that is most sufficient and least costly. The implementation project planning is com...
- Question #287Security Program Management & Operations
The new CISO was informed of all the Information Security projects that the organization has in progress. Two projects are over a year behind schedule and over budget. Using best b...
project managementscope verificationbudget overrunsecurity projects - Question #288
Involvement of senior management is MOST important in the development of:
- Question #289Strategic Planning, Finance, Procurement, and Vendor Management
Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate c...
Risk AssessmentCost-Benefit AnalysisRisk MitigationControl Selection - Question #290
Scenario: Your organization employs single sign-on (user name and password only) as a convenience to your employees to access organizational systems and data. Permission to individ...
- Question #291
The Annualized Loss Expectancy (Before) minus Annualized Loss Expectancy (After) minus Annual Safeguard Cost is the formula for determining:
- Question #292Security Program Management & Operations
What are the primary reasons for the development of a business case for a security project?
business caserisk communicationresource forecastingsecurity investment - Question #293
Scenario: The new CISO was informed of all the Information Security projects that the section has in progress. Two projects are over a year behind schedule and way over budget. Usi...
- Question #294IS Management Controls and Auditing Management
Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate c...
audit frequencycontrol verificationrisk assessmentsecurity controls - Question #295
Scenario: Your program is developed around minimizing risk to information by focusing on people, technology, and operations. You have decided to deal with risk to information from...
- Question #296
Which of the following is MOST useful when developing a business case for security initiatives?
- Question #297Information Security Core Competencies
SCENARIO: Critical servers show signs of erratic behavior within your organization's intranet. Initial information indicates the systems are under attack from an outside entity. As...
incident responsefollow-up phaselessons learnedrecurrence prevention - Question #298Governance (Policy, Legal & Compliance)
Acceptable levels of information security risk tolerance in an organization should be determined by?
Risk ToleranceGovernanceExecutive OversightRisk Appetite - Question #299
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used a...
- Question #300Security Program Management & Operations
One of the MAIN goals of a Business Continuity Plan is to
Business Continuity PlanningDisaster RecoveryProcess RecoveryResilience Planning