Summer Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the ECCouncil CCISO 712-50 Questions and answers with Dumpstech

Exam 712-50 Premium Access

View all detail and faqs for the 712-50 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 12 out of 13 pages
Viewing questions 166-180 out of questions
Questions # 166:

When a critical vulnerability has been discovered on production systems and needs to be fixed immediately, what is the BEST approach for a CISO to mitigate the vulnerability under tight budget constraints?

Options:

A.

Transfer financial resources from other critical programs

B.

Take the system off line until the budget is available

C.

Deploy countermeasures and compensating controls until the budget is available

D.

Schedule an emergency meeting and request the funding to fix the issue

Questions # 167:

Which of the following is a PRIMARY purpose of a Security Operations Center (SOC)?

Options:

A.

Supporting the help desk

B.

Providing risk assessments

C.

Monitoring infrastructure

D.

Providing automatic security alerts

Questions # 168:

You are just hired as the new CISO and are being briefed on all the Information Security projects that your section has on going. You discover that most projects are behind schedule and over budget.

Using the best business practices for project management you determine that the project correctly aligns with the company goals and the scope of the project is correct. What is the NEXT step?

Options:

A.

Review time schedules

B.

Verify budget

C.

Verify resources

D.

Verify constraints

Questions # 169:

Which of the following is a weakness of an asset or group of assets that can be exploited by one or more threats?

Options:

A.

Threat

B.

Vulnerability

C.

Attack vector

D.

Exploitation

Questions # 170:

An organization has decided to develop an in-house BCM capability. The organization has determined it is best to follow a BCM standard published by the International Organization for Standardization (ISO).

The BEST ISO standard to follow that outlines the complete lifecycle of BCM is?

Options:

A.

ISO 22318 Supply Chain Continuity

B.

ISO 27031 BCM Readiness

C.

ISO 22301 BCM Requirements

D.

ISO 22317 BIA

Questions # 171:

What is the estimate of all direct and indirect costs associated with an asset or acquisition over its entire life cycle?

Options:

A.

Total COST of Product

B.

Total Cost of Ownership

C.

Return on Investment

D.

Total Cost of Production

Questions # 172:

What is a key goal of information security?

Options:

A.

Creation of controls and processes to security the organization's data and information resources

B.

The documentation and qualification of risk be the organization to facilitate better decision making by management

C.

The confidentiality, integrity, and availability of the organization s data and information resources

D.

to reduce adverse impacts on the organization to an acceptable level of risk

Questions # 173:

SCENARIO: A CISO has several two-factor authentication systems under review and selects the one that is most sufficient and least costly. The implementation project planning is completed and the teams are ready to implement the solution. The CISO then discovers that the product it is not as scalable as originally thought and will not fit the organization’s needs.

The CISO discovers the scalability issue will only impact a small number of network segments. What is the next logical step to ensure the proper application of risk management methodology within the two-facto implementation project?

Options:

A.

Create new use cases for operational use of the solution

B.

Determine if sufficient mitigating controls can be applied

C.

Decide to accept the risk on behalf of the impacted business units

D.

Report the deficiency to the audit team and create process exceptions

Questions # 174:

Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate controls. You assign work to your staff to create or adjust existing security controls to ensure they are adequate for risk mitigation needs.

When adjusting the controls to mitigate the risks, how often should the CISO perform an audit to verify the controls?

Options:

A.

Annually

B.

Semi-annually

C.

Quarterly

D.

Never

Questions # 175:

Which of the following has the PRIMARY responsibility for determining access rights requirements to information?

Options:

A.

Chief Information Officer (CIO)

B.

Data owner

C.

Database engineer

D.

Chief Information Security Officer (CISO)

Questions # 176:

A newly-hired CISO needs to understand the organization’s financial management standards for business units

and operations. Which of the following would be the best source of this information?

Options:

A.

The internal accounting department

B.

The Chief Financial Officer (CFO)

C.

The external financial audit service

D.

The managers of the accounts payables and accounts receivables teams

Questions # 177:

Which of the following represents the BEST method of ensuring security program alignment to business needs?

Options:

A.

Create a comprehensive security awareness program and provide success metrics to business units

B.

Create security consortiums, such as strategic security planning groups, that include business unit participation

C.

Ensure security implementations include business unit testing and functional validation prior to production rollout

D.

Ensure the organization has strong executive-level security representation through clear sponsorship or the creation of a CISO role

Questions # 178:

What does a security control objective provide for auditors?

Options:

A.

Policy guidance for controls and implementations

B.

Desired results or purpose of implementing a specific control

C.

Techniques that were used for securing information

D.

The framework for the audit control object checklist

Questions # 179:

Your company has limited resources to spend on security initiatives. The Chief Financial Officer asks you to prioritize the protection of information resources based on their value to the company. It is essential that you be able to communicate in language that your fellow executives will understand. You should:

Options:

A.

Create timelines for mitigation

B.

Develop a cost-benefit analysis

C.

Calculate annual loss expectancy

D.

Create a detailed technical executive summary

Questions # 180:

What is the MOST probable explanation for a security policy that is often ignored and unenforced?

Options:

A.

Lack of formal risk management capabilities

B.

Lack of proper policy governance

C.

Lack of a formal security awareness program policy

D.

Lack of formal definition of roles and responsibilities within the policy

Viewing page 12 out of 13 pages
Viewing questions 166-180 out of questions