712-50 Exam Questions
505 real 712-50 exam questions with expert-verified answers and explanations. Page 9 of 11.
- Question #401
What process defines the framework of rules and practices by which a board of directors ensure accountability, fairness and transparency in an organization's relationship with its...
- Question #402Security Program Management & Operations
As the Business Continuity Coordinator of a financial services organization, you are responsible for ensuring assets are recovered timely in the event of a disaster. Which is the B...
disaster recoveryRTOrecovery performance indicatorsbusiness continuity - Question #403Strategic Planning, Finance, Procurement, and Vendor Management
What are the three hierarchically related aspects of strategic planning and in which order should they be done?
strategic planning hierarchyenterprise planningIT strategycybersecurity strategy - Question #404
Which regulation or policy governs protection of personally identifiable user data gathered during a cyber investigation?
- Question #405IS Management Controls and Auditing Management
Which of the following would negatively impact a log analysis of a multinational organization?
log managementtime synchronizationlog analysismultinational operations - Question #406Security Program Management & Operations
Which of the following statements below regarding Key Performance indicators (KPIs) are true?
KPIsperformance metricssecurity program measurementorganizational standards - Question #407Governance (Policy, Legal & Compliance)
When information security falls under the Chief Information Officer (CIO), what is their MOST essential role?
CIO strategic accountabilitysecurity governanceIT leadershiporganizational oversight - Question #408
ABC Limited has recently suffered a security breach with customers' social security number available on the dark web for sale. The CISO, during the time of the incident, has been f...
- Question #409
An organization recently acquired a Data Loss Prevention (DLP) solution, and two months after the implementation, it was found that sensitive data was posted to numerous Dark Web s...
- Question #410Security Program Management & Operations
The main purpose of the SOC is:
SOCSecurity OperationsIncident DetectionOperational Coordination - Question #411Governance (Policy, Legal & Compliance)
When obtaining new products and services, why is it essential to collaborate with lawyers, IT security professionals, privacy professionals, security engineers, suppliers, and othe...
vendor managementcompliance frameworksmulti-stakeholder procurementregulatory risk mitigation - Question #412Information Security Core Competencies
A cloud computing environment that is bound together by technology that allows data and applications to be shared between public and private clouds is BEST referred to as a?
cloud computinghybrid cloudpublic cloudprivate cloud - Question #413Strategic Planning, Finance, Procurement, and Vendor Management
When reviewing a Solution as a Service (SaaS) provider's security health and posture, which key document should you review?
SOC-2 audit reportsSaaS vendor assessmentSecurity due diligenceCompliance frameworks - Question #414Strategic Planning, Finance, Procurement, and Vendor Management
As the Risk Manager of an organization, you are task with managing vendor risk assessments. During the assessment, you identified that the vendor is engaged with high profiled clie...
Vendor Risk ManagementReputation RiskRisk ClassificationBrand Impact - Question #415
What is a Statement of Objectives (SOA)?
- Question #416Security Program Management & Operations
During a cyber incident, which non-security personnel might be needed to assist the security team?
incident responsenon-security personnelcyber incident coordinationteam roles - Question #417Governance (Policy, Legal & Compliance)
With a focus on the review and approval aspects of board responsibilities, the Data Governance Council recommends that the boards provide strategic oversight regarding information...
data governanceboard oversightinformation security governancestrategic oversight - Question #418Information Security Core Competencies
You are the CISO for an investment banking firm. The firm is using artificial intelligence (AI) to assist in approving clients for loans. Which control is MOST important to protect...
AI securitydataset sanitizationdata integrityAI model protection - Question #419Information Security Core Competencies
Which level of data destruction applies logical techniques to sanitize data in all user-addressable storage locations?
data sanitizationdata destruction levelsclearlogical sanitization - Question #420Security Program Management & Operations
A university recently hired a CISO. One of the first tasks is to develop a continuity of operations plan (COOP). In developing the business impact assessment (BIA), which of the fo...
business impact analysisRTOdata backup and recoverycontinuity planning - Question #421
A key cybersecurity feature of a Personal Identification Verification (PIV) Card is:
- Question #422Information Security Core Competencies
When performing a forensic investigation, what are the two MOST common data sources for obtaining evidence from a computer and mobile devices?
digital forensicsvolatile datapersistent dataevidence collection - Question #423
To make sure that the actions of all employees, applications, and systems follow the organization's rules and regulations can BEST be described as which of the following?
- Question #424Governance (Policy, Legal & Compliance)
You have been hired as the Information System Security Officer (ISSO) for a US federal government agency. Your role is to ensure the security posture of the system is maintained. O...
system security planFISMAfederal complianceISSO - Question #425Governance (Policy, Legal & Compliance)
Who should be involved in the development of an internal campaign to address email phishing?
Security AwarenessPhishing PreventionExecutive GovernanceStakeholder Management - Question #426
Of the following types of SOCs (Security Operations Centers), which one would be MOST likely used if the CISO has decided to outsource the infrastructure and administration of it?
- Question #427
Many successful cyber-attacks currently include:
- Question #428Strategic Planning, Finance, Procurement, and Vendor Management
When evaluating a Managed Security Services Provider (MSSP), which service(s) is/are most important:
MSSP evaluationvendor selectionsecurity outsourcingservice tailoring - Question #429Security Program Management & Operations
Which of the following strategies provides the BEST response to a ransomware attack?
ransomware responsebackup strategyincident recoverybusiness continuity - Question #430Security Program Management & Operations
What is the MOST critical output of the incident response process?
Incident ResponsePost-Incident ReviewLessons LearnedContinuous Improvement - Question #431IS Management Controls and Auditing Management
Who is responsible for verifying that audit directives are implemented?
Internal AuditAudit VerificationAudit GovernanceCompliance Assurance - Question #432Governance (Policy, Legal & Compliance)
XYZ is a publicly-traded software development company. Who is ultimately accountable to the shareholders in the event of a cybersecurity breach?
CISO accountabilityorganizational governancecybersecurity breachexecutive responsibility - Question #433
What organizational structure combines the functional and project structures to create a hybrid of the two?
- Question #434IS Management Controls and Auditing Management
The primary responsibility for assigning entitlements to a network share lies with which role?
data ownershipaccess entitlementsroles and responsibilitiesaccess control - Question #435Security Program Management & Operations
What does RACI stand for?
RACI matrixroles and responsibilitiesproject managementaccountability - Question #436Information Security Core Competencies
What key technology can mitigate ransomware threats?
ransomware mitigationimmutable storagedata protectionthreat mitigation - Question #437Security Program Management & Operations
Which of the following are the triple constraints of project management?
triple constraintsproject managementscopecost and time - Question #438Information Security Core Competencies
A Security Operations (SecOps) Manager is considering implementing threat hunting to be able to make better decisions on protecting information and assets. What is the MAIN goal of...
threat huntingSecOpsevent detectionproactive defense - Question #439
A bastion host should be placed:
- Question #440
Optical biometric recognition such as retina scanning provides access to facilities through reading the unique characteristics of a person's eye. However, authorization failures ca...
- Question #441Strategic Planning, Finance, Procurement, and Vendor Management
The Board of Directors of a publicly-traded company is concerned about the security implications of a strategic project that will migrate 50% of the organization's information tech...
earned value managementcost varianceproject budgetcloud migration - Question #442Governance (Policy, Legal & Compliance)
What is the primary difference between regulations and standards?
Regulations vs StandardsLegal EnforcementComplianceGovernance - Question #443
A Security Operations Manager is finding it difficult to maintain adequate staff levels to monitor security operations during off-hours. To reduce the impact of staff shortages and...
- Question #444Security Program Management & Operations
As the CISO, you are the project sponsor for a highly visible log management project. The objective of the project is to centralize all the enterprise logs into a security informat...
quality auditsPMBOK process groupsSIEMproject execution - Question #445IS Management Controls and Auditing Management
A CISO must conduct risk assessments using a method where the Chief Financial Officer (CFO) receives impact data in financial terms to use as input to select the proper level of co...
quantitative risk assessmentfinancial impactrisk analysiscyber insurance - Question #446
What is a key policy that should be part of the information security plan?
- Question #447Information Security Core Competencies
Which of the following is the MOST effective method to counter phishing attacks?
phishing mitigationsecurity awareness trainingsocial engineeringuser behavior - Question #448Governance (Policy, Legal & Compliance)
You have been promoted to the CISO of a big-box retail store chain reporting to the Chief Information Officer (CIO). The CIO's first mandate to you is to develop a cybersecurity co...
PCI DSScompliance frameworkretail securitypayment card industry - Question #449Strategic Planning, Finance, Procurement, and Vendor Management
In defining a strategic security plan for an organization, what should a CISO first analyze?
strategic planningorganizational alignmentCISO strategysecurity roadmap - Question #450
An auditor is reviewing the security classifications for a group of assets and finds that many of the assets are not correctly classified. What should the auditor's NEXT step be?