Exambible 712-50 Questions are updated and all 712-50 answers are verified by experts. Once you have completely prepared with our 712-50 exam prep kits you will be ready for the real 712-50 exam without a problem. We have Rebirth EC-Council 712-50 dumps study guide. PASSED 712-50 First attempt! Here What I Did.

Q181.  - (Topic 1)

When an organization claims it is secure because it is PCI-DSS certified, what is a good first question to ask towards assessing the effectiveness of their security program?

A. How many credit card records are stored?

B. How many servers do you have?

C. What is the scope of the certification?

D. What is the value of the assets at risk?

Answer: C


Q182.  - (Topic 2)

Creating a secondary authentication process for network access would be an example of?

A. Nonlinearities in physical security performance metrics

A. B. Defense in depth cost enumerated costs

C. System hardening and patching requirements

D. Anti-virus for mobile devices

Answer: A


Q183.  - (Topic 2)

To have accurate and effective information security policies how often should the CISO review the organization policies?

A. Every 6 months

B. Quarterly

C. Before an audit

D. At least once a year

Answer: D


Q184.  - (Topic 4)

The general ledger setup function in an enterprise resource package allows for setting accounting periods. Access to this function has been permitted to users in finance, the shipping department, and production scheduling. What is the most likely reason for such broad access?

A. The need to change accounting periods on a regular basis.

B. The requirement to post entries for a closed accounting period.

C. The need to create and modify the chart of accounts and its allocations.

A. D. The lack of policies and procedures for the proper segregation of duties.

Answer: D


Q185.  - (Topic 2)

The amount of risk an organization is willing to accept in pursuit of its mission is known as

A. Risk mitigation

B. Risk transfer

C. Risk tolerance

D. Risk acceptance

Answer: C


Q186.  - (Topic 2)

You have implemented the new controls. What is the next step?

A. Document the process for the stakeholders

B. Monitor the effectiveness of the controls

C. Update the audit findings report

D. Perform a risk assessment

Answer: B


Q187.  - (Topic 4)

Your incident handling manager detects a virus attack in the network of your company. You develop a signature based on the characteristics of the detected virus. Which of the following phases in the incident handling process will utilize the signature to resolve this incident?

A. Containment

B. Recovery

C. Identification

D. Eradication

Answer: D


Q188.  - (Topic 3)

An organization has a stated requirement to block certain traffic on networks. The

implementation of controls will disrupt a manufacturing process and cause unacceptable delays, resulting in sever revenue disruptions. Which of the following is MOST likely to be responsible for accepting the risk until mitigating controls can be implemented?

A. The CISO

B. Audit and Compliance

C. The CFO

D. The business owner

Answer: D


Q189. - (Topic 1)

One of the MAIN goals of a Business Continuity Plan is to

A. Ensure all infrastructure and applications are available in the event of a disaster

B. Allow all technical first-responders to understand their roles in the event of a disaster

C. Provide step by step plans to recover business processes in the event of a disaster

D. Assign responsibilities to the technical teams responsible for the recovery of all data.

Answer: C


Q190. - (Topic 1)

A security manager has created a risk program. Which of the following is a critical part of ensuring the program is successful?

A. Providing a risk program governance structure

B. Ensuring developers include risk control comments in code

C. Creating risk assessment templates based on specific threats

D. Allowing for the acceptance of risk for regulatory compliance requirements

Answer: A


Q191.  - (Topic 2)

Assigning the role and responsibility of Information Assurance to a dedicated and independent security group is an example of:

A. Detective Controls

B. Proactive Controls

C. Preemptive Controls

D. Organizational Controls

Answer: D


Q192.  - (Topic 3)

When operating under severe budget constraints a CISO will have to be creative to maintain a strong security organization. Which example below is the MOST creative way to maintain a strong security posture during these difficult times?

A. Download open source security tools and deploy them on your production network

B. Download trial versions of commercially available security tools and deploy on your production network

C. Download open source security tools from a trusted site, test, and then deploy on production network

D. Download security tools from a trusted source and deploy to production network

Answer: C


Q193.  - (Topic 5)

Your company has limited resources to spend on security initiatives. The Chief Financial Officer asks you to prioritize the protection of information resources based on their value to the company. It is essential that you be able to communicate in language that your fellow executives will understand. You should:

A. Create timelines for mitigation

B. Develop a cost-benefit analysis

C. Calculate annual loss expectancy

D. Create a detailed technical executive summary

Answer: B


Q194.  - (Topic 3)

To get an Information Security project back on schedule, which of the following will provide the MOST help?

A. Upper management support

B. More frequent project milestone meetings

C. Stakeholder support

D. Extend work hours

Answer: A


Q195.  - (Topic 2)

When working in the Payment Card Industry (PCI), how often should security logs be review to comply with the standards?

A. Daily

B. Hourly

C. Weekly

D. Monthly

Answer: A