[Sep-2021] Valid Way To Pass EC-COUNCIL Exam Dumps with 712-50 Exam Study Guide [Q77-Q94]

Share

[Sep-2021] Valid Way To Pass EC-COUNCIL Exam Dumps with 712-50 Exam Study Guide

All 712-50 Dumps and EC-Council Certified CISO (CCISO) Training Courses Help candidates to study and pass the Exams hassle-free!

NEW QUESTION 77
An application vulnerability assessment has identified a security flaw in an application. This is a flaw that was previously identified and remediated on a prior release of the application. Which of the following is MOST likely the reason for this recurring issue?

  • A. Lack of change management controls
  • B. High turnover in the application development department
  • C. Lack of version/source controls
  • D. Ineffective configuration management controls

Answer: C

 

NEW QUESTION 78
Which of the following is a benefit of a risk-based approach to audit planning?

  • A. Resources are allocated to the areas of the highest concern
  • B. Scheduling may be performed months in advance
  • C. Budgets are more likely to be met by the IT audit staff
  • D. Staff will be exposed to a variety of technologies

Answer: A

Explanation:
ECCouncil 712-50 : Practice Test

 

NEW QUESTION 79
How often should the Statements of Standards for Attestation Engagements-16 (SSAE16)/International Standard on Assurance Engagements 3402 (ISAE3402) report of your vendors be reviewed?

  • A. Bi-annually
  • B. Semi-annually
  • C. Annually
  • D. Quarterly

Answer: C

 

NEW QUESTION 80
Your company has a "no right to privacy" notice on all logon screens for your information
systems and users sign an Acceptable Use Policy informing them of this condition. A peer group member and friend comes to you and requests access to one of her employee's email account. What should you do? (choose the BEST answer):

  • A. Assist her with the request, but only after her supervisor signs off on the action.
  • B. Grant her access, the employee has been adequately warned through the AUP.
  • C. Deny the request citing national privacy laws.
  • D. Reset the employee's password and give it to the supervisor.

Answer: A

 

NEW QUESTION 81
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used as audit baselines. The audit report was presented to the CISO and a variety of high, medium and low rated gaps were identified.
The CISO has implemented remediation activities. Which of the following is the MOST logical next step?

  • A. Report the audit findings and remediation status to business stake holders
  • B. Validate security program resource requirements
  • C. Review security procedures to determine if they need modified according to findings Scenario5
  • D. Validate the effectiveness of applied controls

Answer: D

 

NEW QUESTION 82
Control Objectives for Information and Related Technology (COBIT) is which of the following?

  • A. An Information Security audit standard
  • B. A framework for Information Technology management and governance
  • C. A set of international regulations for Information Technology governance
  • D. An audit guideline for certifying secure systems and controls

Answer: B

 

NEW QUESTION 83
You are the CISO of a commercial social media organization. The leadership wants to rapidly create new methods of sharing customer data through creative linkages with mobile devices. You have voiced concern about privacy regulations but the velocity of the business is given priority. Which of the following BEST describes this organization?

  • A. Risk conditional
  • B. Risk minimal
  • C. Risk averse
  • D. Risk tolerant

Answer: D

 

NEW QUESTION 84
When entering into a third party vendor agreement for security services, at what point in the process is it BEST to understand and validate the security posture and compliance level of the vendor?

  • A. Prior to signing the agreement and before any security services are being performed
  • B. Once the agreement has been signed and the security vendor states that they will need access to the network
  • C. Once the vendor is on premise and before they perform security services
  • D. At the time the security services are being performed and the vendor needs access to the network

Answer: A

 

NEW QUESTION 85
If a Virtual Machine's (VM) data is being replicated and that data is corrupted, this corruption will automatically be replicated to the other machine(s). What would be the BEST control to safeguard data integrity?

  • A. Maintain separate VM backups
  • B. Backup to a remote location
  • C. Backup to tape
  • D. Increase VM replication frequency

Answer: A

 

NEW QUESTION 86
When would it be more desirable to develop a set of decentralized security policies and procedures within an enterprise environment?

  • A. When the enterprise is made up of many business units with diverse business activities, risks profiles and regulatory requirements.
  • B. When there is a variety of technologies deployed in the infrastructure.
  • C. When there is a need to develop a more unified incident response capability.
  • D. When it results in an overall lower cost of operating the security program.

Answer: A

 

NEW QUESTION 87
In effort to save your company money which of the following methods of training results in the lowest cost for the organization?

  • A. One-One Training
  • B. Distance learning/Web seminars
  • C. Formal Class
  • D. Self -Study (noncomputerized)

Answer: D

 

NEW QUESTION 88
Who in the organization determines access to information?

  • A. Legal department
  • B. Compliance officer
  • C. Data Owner
  • D. Information security officer

Answer: C

 

NEW QUESTION 89
Your company has limited resources to spend on security initiatives. The Chief Financial Officer asks you to prioritize the protection of information resources based on their value to the company. It is essential that you be able to communicate in language that your fellow executives will understand. You should:

  • A. Develop a cost-benefit analysis
  • B. Create a detailed technical executive summary
  • C. Create timelines for mitigation
  • D. Calculate annual loss expectancy

Answer: A

 

NEW QUESTION 90
What role should the CISO play in properly scoping a PCI environment?

  • A. Work with a Qualified Security Assessor (QSA) to determine the scope of the PCI environment
  • B. Complete the self-assessment questionnaire and work with an Approved Scanning Vendor (ASV) to determine scope
  • C. Validate the business units' suggestions as to what should be included in the scoping process
  • D. Ensure internal scope validation is completed and that an assessment has been done to discover all credit card data

Answer: D

 

NEW QUESTION 91
Which type of physical security control scan a person's external features through a digital video camera before granting access to a restricted area?

  • A. Iris scan
  • B. Facial recognition scan
  • C. Signature kinetics scan
  • D. Retinal scan

Answer: B

 

NEW QUESTION 92
What is the SECOND step to creating a risk management methodology according to the National Institute of Standards and Technology (NIST) SP 800-30 standard?

  • A. Determine appetite
  • B. Perform a risk assessment
  • C. Mitigate risk
  • D. Evaluate risk avoidance criteria

Answer: C

 

NEW QUESTION 93
As the CISO you need to write the IT security strategic plan.
Which of the following is the MOST important to review before you start writing the plan?

  • A. The company business plan
  • B. The existing IT environment
  • C. The present IT budget
  • D. Other corporate technology trends

Answer: A

 

NEW QUESTION 94
......

Real Exam Questions & Answers - EC-COUNCIL 712-50 Dump is Ready: https://drive.google.com/open?id=12-LNAlsUeISk7BJHkKvyDIuznC8e1-r4

Get Latest [Sep-2021] Conduct effective penetration tests using  Actual4dump 712-50