
[Jan 27, 2022] EC-COUNCIL 712-50 Real Exam Questions and Answers FREE
Pass EC-COUNCIL 712-50 Exam Info and Free Practice Test
What is the duration of the 712-50 Exam
- Passing Score: 70%
- Length of Examination: 2.5 hours
- Number of Questions: 150
- Format: Multiple choices, multiple answers
NEW QUESTION 138
The Information Security Management program MUST protect:
- A. critical business processes and revenue streams
- B. Audit schedules and findings
- C. all organizational assets
- D. Intellectual property released into the public domain
Answer: A
NEW QUESTION 139
Which of the following is considered one of the most frequent failures in project management?
- A. Overly restrictive management
- B. Excessive personnel on project
- C. Failure to meet project deadlines
- D. Insufficient resources
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION 140
Which of the following is the MOST important for a CISO to understand when identifying threats?
- A. How the firewall and other security devices are configured to prevent attacks
- B. How the incident management team prepares to handle an attack
- C. How vulnerabilities can potentially be exploited in systems that impact the organization
- D. How the security operations team will behave to reported incidents
Answer: C
NEW QUESTION 141
If the result of an NPV is positive, then the project should be selected. The net present value shows the present value of the project, based on the decisions taken for its selection. What is the net present value equal to?
- A. Initial investment - Future value
- B. Total investment - Discounted cash
- C. Net profit - per capita income
- D. Average profit - Annual investment
Answer: D
NEW QUESTION 142
As the new CISO at the company you are reviewing the audit reporting process and notice that it includes only detailed technical diagrams. What else should be in the reporting process?
- A. Business charter
- B. Penetration test agreement
- C. Executive summary
- D. Names and phone numbers of those who conducted the audit
Answer: C
NEW QUESTION 143
Which of the following is a critical operational component of an Incident Response Program (IRP)?
- A. Daily monitoring of vulnerability advisories relating to your organization's deployed technologies.
- B. Annual review of program charters, policies, procedures and organizational agreements.
- C. Monthly program tests to ensure resource allocation is sufficient for supporting the needs of the organization
- D. Weekly program budget reviews to ensure the percentage of program funding remains constant.
Answer: A
NEW QUESTION 144
Involvement of senior management is MOST important in the development of:
- A. IT security policies
- B. IT security procedures
- C. Standards and guidelines
- D. IT security implementation plans
Answer: A
NEW QUESTION 145
What two methods are used to assess risk impact?
- A. Qualitative and percent of loss realized
- B. Subjective and Objective
- C. Cost and annual rate of expectance
- D. Quantitative and qualitative
Answer: D
NEW QUESTION 146
Creating good security metrics is essential for a CISO. What would be the BEST sources for creating security metrics for baseline defenses coverage?
- A. Firewall, exchange, web server, intrusion detection system (IDS)
- B. IDS, syslog, router, switches
- C. Firewall, anti-virus console, IDS, syslog
- D. Servers, routers, switches, modem
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION 147
Which one of the following BEST describes which member of the management team is accountable for the day-to-day operation of the information security program?
- A. Security technicians
- B. Security administrators
- C. Security mangers
- D. Security analysts
Answer: C
NEW QUESTION 148
Which of the following is considered the MOST effective tool against social engineering?
- A. Anti-malware tools
- B. Effective Security awareness program
- C. Effective Security Vulnerability Management Program
- D. Anti-phishing tools
Answer: B
NEW QUESTION 149
Which of the following represents the BEST method for obtaining business unit acceptance of security controls within an organization?
- A. Provide the business units with control mandates and schedules of audits for compliance validation
- B. Ensure business units are involved in the creation of controls and defining conditions under which they must be applied
- C. Create separate controls for the business units based on the types of business and functions they perform
- D. Allow the business units to decide which controls apply to their systems, such as the encryption of sensitive data
Answer: B
NEW QUESTION 150
When operating under severe budget constraints a CISO will have to be creative to maintain a strong security organization. Which example below is the MOST creative way to maintain a strong security posture during these difficult times?
- A. Download open source security tools and deploy them on your production network
- B. Download trial versions of commercially available security tools and deploy on your production network
- C. Download open source security tools from a trusted site, test, and then deploy on production network
- D. Download security tools from a trusted source and deploy to production network
Answer: C
NEW QUESTION 151
Which of the following statements about Encapsulating Security Payload (ESP) is true?
- A. It uses TCP port 22 as the default port and operates at the application layer.
- B. It uses UDP port 22
- C. It is an IPSec protocol.
- D. It is a text-based communication protocol.
Answer: C
NEW QUESTION 152
Which International Organization for Standardization (ISO) below BEST describes the performance of risk management, and includes a five-stage risk management methodology.
- A. ISO 27004
- B. ISO 27005
- C. ISO 27001
- D. ISO 27002
Answer: B
NEW QUESTION 153
The patching and monitoring of systems on a consistent schedule is required by?
- A. Local privacy laws
- B. Industry best practices
- C. Audit best practices
- D. Risk Management framework
Answer: D
Explanation:
Explanation
NEW QUESTION 154
A Chief Information Security Officer received a list of high, medium, and low impact audit findings. Which of the following represents the BEST course of action?
- A. If the findings impact regulatory compliance, try to apply remediation that will address the most findings for the least cost.
- B. If the findings impact regulatory compliance, remediate the high findings as quickly as possible.
- C. If the findings do not impact regulatory compliance, remediate only the high and medium risk findings.
- D. If the findings do not impact regulatory compliance, review current security controls.
Answer: B
NEW QUESTION 155
An organization is required to implement background checks on all employees with access to databases containing credit card information. This is considered a security
- A. Management control
- B. Technical control
- C. Procedural control
- D. Administrative control
Answer: A
NEW QUESTION 156
Which of the following are not stakeholders of IT security projects?
- A. Board of directors
- B. Help Desk
- C. Third party vendors
- D. CISO
Answer: C
NEW QUESTION 157
The CIO of an organization has decided to assign the responsibility of internal IT audit to the IT team. This is consider a bad practice MAINLY because
- A. The IT team is not familiar in IT audit practices
- B. This represents a conflict of interest
- C. This represents a bad implementation of the Least Privilege principle
- D. The IT team is not certified to perform audits
Answer: B
NEW QUESTION 158
Which of the following is the MOST important benefit of an effective security governance process?
- A. Reduction of security breaches
- B. Better vendor management
- C. Senior management participation in the incident response process
- D. Reduction of liability and overall risk to the organization
Answer: D
NEW QUESTION 159
A method to transfer risk is to______________.
- A. Purchase breach insurance
- B. Align to business operations
- C. Move operations to another region
- D. Implement redundancy
Answer: A
NEW QUESTION 160
To get an Information Security project back on schedule, which of the following will provide the MOST help?
- A. Extend work hours
- B. Stakeholder support
- C. More frequent project milestone meetings
- D. None
- E. Upper management support
Answer: E
NEW QUESTION 161
......
Ending Notes
To become a dependable Certified CISO, one needs to have a unique blend of IT and leadership qualities that can only be gained with the EC-Council 712-50 exam. It is the key to a secure and promising career. Success in this test will take your career at zeniths and will make you an ideal candidate for information security job roles. But, don’t forget to refer to only quality books from Amazon for self-study. With them, the career path will be easy-to-accomplish and enjoyable.
Know Exam Domains
The entire 712-50 exam structure is based upon the CCISO handbook and overall, there are five exam domains tested. Governance is the first exam topic and it explains notions like information security, trends, changes in information security, best practices, and leadership. Security risk management controls and audits management is what the exam taught next. Under this domain, the learner will have details about designing information security controls and their analysis. The core focus of the third evaluation objective is on security program operations and it throws light on project development, implementation, budgeting, and managing information security teams. Information security fundamental concepts are the title for a further area and it is all about physical security, disaster recovery, firewalls, wireless security, and coding practices. In the last tested part, the learners will be able to know about strategic planning and vendor control, which helps them become professional & more competent IT managers.
Latest 712-50 Exam Dumps EC-COUNCIL Exam: https://www.prep4pass.com/712-50_exam-braindumps.html
New 2022 Latest Questions 712-50 Dumps - Use Updated EC-COUNCIL Exam: https://drive.google.com/open?id=1kRCndhFN3Sy4Nami9i8xs1hOP8IIG2RC
