[Sep 07, 2021] 712-50 Ultimate Study Guide - PracticeTorrent [Q219-Q237]

Share

[Sep 07, 2021] 712-50 Ultimate Study Guide -  PracticeTorrent

Ultimate Guide to Prepare 712-50 Certification Exam for CCISO in 2021

NEW QUESTION 219
A CISO has recently joined an organization with a poorly implemented security program. The desire is to base the security program on a risk management approach. Which of the following is a foundational requirement in order to initiate this type of program?

  • A. A complete inventory of Information Technology assets including infrastructure, networks, applications and data
  • B. A clearly identified executive sponsor who will champion the effort to ensure organizational buy-in
  • C. A security organization that is adequately staffed to apply required mitigation strategies and regulatory compliance solutions
  • D. A clear set of security policies and procedures that are more concept-based than controls-based

Answer: B

 

NEW QUESTION 220
An anonymity network is a series of?

  • A. Government networks in Tora
  • B. Virtual network tunnels
  • C. Covert government networks
  • D. War driving maps

Answer: B

 

NEW QUESTION 221
A stakeholder is a person or group:

  • A. That will ultimately use the system.
  • B. That has budget authority.
  • C. Vested in the success and/or failure of a project or initiative regardless of budget implications.
  • D. Vested in the success and/or failure of a project or initiative and is tied to the project budget.

Answer: C

 

NEW QUESTION 222
Which of the following is the MOST important benefit of an effective security governance process?

  • A. Better vendor management
  • B. Reduction of security breaches
  • C. Senior management participation in the incident response process
  • D. Reduction of liability and overall risk to the organization

Answer: D

 

NEW QUESTION 223
What is meant by password aging?

  • A. The amount of time it takes for a password to activate
  • B. A Single Sign-On requirement
  • C. Time in seconds a user is allocated to change a password
  • D. An expiration date set for passwords

Answer: C

Explanation:
Explanation/Reference: https://medical-dictionary.thefreedictionary.com/password+ageing

 

NEW QUESTION 224
Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate controls. You assign work to your staff to create or adjust existing security controls to ensure they are adequate for risk mitigation needs.
You have identified potential solutions for all of your risks that do not have security controls. What is the NEXT step?

  • A. Create a risk metrics for all unmitigated risks
  • B. Verify that the cost of mitigation is less than the risk
  • C. Get approval from the board of directors
  • D. Screen potential vendor solutions

Answer: B

 

NEW QUESTION 225
When managing the critical path of an IT security project, which of the following is MOST important?

  • A. Knowing the threats to the organization.
  • B. Knowing who all the stakeholders are.
  • C. Knowing the milestones and timelines of deliverables.
  • D. Knowing the people on the data center team.

Answer: C

 

NEW QUESTION 226
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used as audit baselines. The audit report was presented to the CISO and a variety of high, medium and low rated gaps were identified.
After determining the audit findings are accurate, which of the following is the MOST logical next activity?

  • A. Begin initial gap remediation analyses
  • B. Create a briefing of the findings for executive management
  • C. Validate gaps with the Information Technology team
  • D. Review the security organization's charter

Answer: A

 

NEW QUESTION 227
Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small retail merchant but it is expected to grow to a global customer base of many millions of customers in just a few years.
This global retail company is expected to accept credit card payments. Which of the following is of MOST concern when defining a security program for this organization?

  • A. International encryption restrictions
  • B. Compliance to Payment Card Industry (PCI) data security standards
  • C. Adherence to local data breach notification laws
  • D. Compliance with local government privacy laws

Answer: B

 

NEW QUESTION 228
Scenario: An organization has recently appointed a CISO. This is a new role in the organization and it signals the increasing need to address security consistently at the enterprise level. This new CISO, while confident with skills and experience, is constantly on the defensive and is unable to advance the IT security centric agenda.
Which of the following is the reason the CISO has not been able to advance the security agenda in this organization?

  • A. Lack of a security awareness program
  • B. Lack of influence with leaders outside IT
  • C. Lack of identification of technology stake holders
  • D. Lack of business continuity process

Answer: B

 

NEW QUESTION 229
An application vulnerability assessment has identified a security flaw in an application. This is a flaw that was previously identified and remediated on a prior release of the application. Which of the following is MOST likely the reason for this recurring issue?

  • A. Lack of change management controls
  • B. High turnover in the application development department
  • C. Lack of version/source controls
  • D. Ineffective configuration management controls

Answer: C

 

NEW QUESTION 230
Control Objectives for Information and Related Technology (COBIT) is which of the following?

  • A. An Information Security audit standard
  • B. A framework for Information Technology management and governance
  • C. A set of international regulations for Information Technology governance
  • D. An audit guideline for certifying secure systems and controls

Answer: B

 

NEW QUESTION 231
Which of the following tests is performed by an Information Systems (IS) auditor when a sample of programs is selected to determine if the source and object versions are the same?

  • A. A compliance test of program library controls
  • B. Substantive test of program library controls
  • C. A substantive test of the program compiler controls
  • D. A compliance test of the program compiler controls

Answer: A

 

NEW QUESTION 232
Smith, the project manager for a larger multi-location firm, is leading a software project team that has 18 members, 5 of which are assigned to testing. Due to recent recommendations by an organizational quality audit team, the project manager is convinced to add a quality professional to lead to test team at additional cost to the project.
The project manager is aware of the importance of communication for the success of the project and takes the step of introducing additional communication channels, making it more complex, in order to assure quality levels of the project. What will be the first project management document that Smith should change in order to accommodate additional communication channels?

  • A. Scope statement
  • B. Risk management plan
  • C. WBS document
  • D. Change control document

Answer: C

Explanation:
Explanation/Reference:

 

NEW QUESTION 233
The single most important consideration to make when developing your security program, policies, and processes is:

  • A. Streaming for efficiency
  • B. Budgeting for unforeseen data compromises
  • C. Establishing your authority as the Security Executive
  • D. Alignment with the business

Answer: D

 

NEW QUESTION 234
The alerting, monitoring and life-cycle management of security related events is typically handled by the

  • A. risk management process
  • B. risk assessment process
  • C. governance, risk, and compliance tools
  • D. security threat and vulnerability management process

Answer: D

 

NEW QUESTION 235
A new CISO just started with a company and on the CISO's desk is the last complete Information Security Management audit report. The audit report is over two years old.
After reading it, what should be the CISO's FIRST priority?

  • A. Contract with an external audit company to conduct an unbiased audit
  • B. Meet with audit team to determine a timeline for corrections
  • C. Have internal audit conduct another audit to see what has changed.
  • D. Review the recommendations and follow up to see if audit implemented the changes

Answer: D

 

NEW QUESTION 236
A severe security threat has been detected on your corporate network. As CISO you quickly assemble key members of the Information Technology team and business operations to determine a modification to security controls in response to the threat. This is an example of:

  • A. Change management
  • B. Thought leadership
  • C. Business continuity planning
  • D. Security Incident Response

Answer: D

 

NEW QUESTION 237
......

CCISO Fundamentals-712-50 Exam-Practice-Dumps: https://www.practicetorrent.com/712-50-practice-exam-torrent.html

Use Real 712-50 Dumps - EC-COUNCIL Correct Answers: https://drive.google.com/open?id=1O_szOhx5bPLrKbZHaOOBAR2cZCvq-dvZ