712-50 Exam Questions
505 real 712-50 exam questions with expert-verified answers and explanations. Page 7 of 11.
- Question #301
A security manager has created a risk program. Which of the following is a critical part of ensuring the program is successful?
- Question #302
Regulatory requirements typically force organizations to implement
- Question #303Governance (Policy, Legal & Compliance)
You have purchased a new insurance policy as part of your risk strategy. Which of the following risk strategy options have you engaged in?
Risk TransferInsuranceRisk ManagementRisk Strategy - Question #304
Credit card information, medical data, and government records are all examples of:
- Question #305
A global retail company is creating a new compliance management process. Which of the following regulations is of MOST importance to be tracked and managed by this process?
- Question #306IS Management Controls and Auditing Management
Which of the following are the MOST important factors for proactively determining system vulnerabilities?
vulnerability assessmentpenetration testingproactive securitysecurity controls - Question #307Governance (Policy, Legal & Compliance)
Which of the following is MOST likely to be discretionary?
governance structurespolicy vs guidelinesdiscretionary controlssecurity governance - Question #308
You have implemented a new security control. Which of the following risk strategy options have you engaged in?
- Question #309
According to the National Institute of Standards and Technology (NIST) SP 800-40, which of the following considerations are MOST important when creating a vulnerability management...
- Question #310
Risk is defined as:
- Question #311
Who in the organization determines access to information?
- Question #312
Which of the following is the MOST important benefit of an effective security governance process?
- Question #313
Which of the following most commonly falls within the scope of an information security governance steering committee?
- Question #314
What is a difference from the list below between quantitative and qualitative Risk Assessment?
- Question #315
Which of the following is the MAIN reason to follow a formal risk management process in an organization that hosts and uses privately identifiable information (PII) as part of thei...
- Question #316
Which of the following is the MOST important for a CISO to understand when identifying threats?
- Question #317
The success of the Chief Information Security Officer is MOST dependent upon:
- Question #318
The Information Security Governance program MUST:
- Question #319
A method to transfer risk is to:
- Question #320Governance (Policy, Legal & Compliance)
An organization information security policy serves to
information security policyacceptable useuser behaviorgovernance - Question #321Security Program Management & Operations
Which of the following methodologies references the recommended industry standard that Information security project managers should follow?
Project Management (PMBOK)IS Project ManagementIndustry StandardsMethodology - Question #322Security Program Management & Operations
Which one of the following BEST describes which member of the management team is accountable for the day-to-day operation of the information security program?
security-rolesmanagement-structureoperational-accountabilitysecurity-management - Question #323Governance (Policy, Legal & Compliance)
The ultimate goal of an IT security projects is:
business alignmentsecurity governanceproject objectivesstrategy - Question #324
A stakeholder is a person or group:
- Question #325Security Program Management & Operations
Which of the following represents the best method of ensuring business unit alignment with security program requirements?
Business Unit AlignmentSecurity Program ManagementCollaborative Risk ManagementStakeholder Engagement - Question #326
A severe security threat has been detected on your corporate network. As CISO you quickly assemble key members of the Information Technology team and business operations to determi...
- Question #327Security Program Management & Operations
In effort to save your company money which of the following methods of training results in the lowest cost for the organization?
security trainingcost managementawareness programtraining methods - Question #328Security Program Management & Operations
When managing the critical path of an IT security project, which of the following is MOST important?
Critical Path ManagementProject SchedulingIT Security ProjectsMilestone Tracking - Question #329
When entering into a third party vendor agreement for security services, at what point in the process is it BEST to understand and validate the security posture and compliance leve...
- Question #330Information Security Core Competencies
In order for a CISO to have true situational awareness there is a need to deploy technology that can give a real-time view of security events across the enterprise. Which tool sele...
SIEMsituational awarenesssecurity monitoringIDS - Question #331Security Program Management & Operations
You currently cannot provide for 24/7 coverage of your security monitoring and incident response duties and your company is resistant to the idea of adding more full-time employees...
Managed Security Services24/7 OperationsIncident ResponseResource Management - Question #332Security Program Management & Operations
Which of the following are not stakeholders of IT security projects?
stakeholder managementIT security governanceproject managementorganizational structure - Question #333
What should an organization do to ensure that they have a sound Business Continuity (BC) Plan?
- Question #334
When choosing a risk mitigation method what is the MOST important factor?
- Question #335
What is the BEST way to achieve on-going compliance monitoring in an organization?
- Question #336Security Program Management & Operations
Risk appetite directly affects what part of a vulnerability management program?
Risk AppetiteVulnerability ManagementProgram ScopeRisk Management - Question #337Information Security Core Competencies
Which of the following is a critical operational component of an Incident Response Program (IRP)?
incident response programvulnerability monitoringoperational IRPadvisory monitoring - Question #338
When briefing senior management on the creation of a governance process, the MOST important aspect should be:
- Question #339
After a risk assessment is performed, a particular risk is considered to have the potential of costing the organization 1.2 Million USD. This is an example of
- Question #340
Why is it vitally important that senior management endorse a security policy?
- Question #341
The purpose of NIST SP 800-53 as part of the NIST System Certification and Accreditation Project is to establish a set of standardized, minimum security controls for IT systems add...
- Question #342Information Security Core Competencies
The exposure factor of a threat to your organization is defined by?
Exposure FactorQuantitative Risk AnalysisThreat AssessmentAsset Loss - Question #343Security Program Management & Operations
A company wants to fill a Chief Information Security Officer position in the organization. They need to define and implement a more holistic security program. Which of the followin...
CISO qualificationsprogram managementsecurity leadershipindustry certifications - Question #344
Which of the following is MOST important when dealing with an Information Security Steering committee:
- Question #345Governance (Policy, Legal & Compliance)
Which of the following has the GREATEST impact on the implementation of an information security governance model?
organizational_structuregovernance_implementationcontrol_frameworkgovernance_model_design - Question #346Information Security Core Competencies
Which of the following statements about Encapsulating Security Payload (ESP) is true?
IPSecESPVPN protocolsnetwork encryption - Question #347
What type of attack requires the least amount of technical equipment and has the highest success rate?
- Question #348
Your penetration testing team installs an in-line hardware key logger onto one of your network machines. Which of the following is of major concern to the security organization?
- Question #349
File Integrity Monitoring (FIM) is considered a
- Question #350Strategic Planning, Finance, Procurement, and Vendor Management
SCENARIO: A CISO has several two-factor authentication systems under review and selects the one that is most sufficient and least costly. The implementation project planning is com...
risk assessmentvendor evaluationproof of concepttechnology procurement