It is impossible to pass EC-Council 712-50 exam without any help in the short term. Come to Ucertify soon and find the most advanced, correct and guaranteed EC-Council 712-50 practice questions. You will get a surprising result by our Most recent EC-Council Certified CISO (CCISO) practice guides.

Q136.  - (Topic 5)

Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small retail merchant but it is expected to grow to a global customer base of many millions of customers in just a few years.

The organization has already been subject to a significant amount of credit card fraud. Which of the following is the MOST likely reason for this fraud?

A. Lack of compliance to the Payment Card Industry (PCI) standards

B. Ineffective security awareness program

C. Security practices not in alignment with ISO 27000 frameworks

D. Lack of technical controls when dealing with credit card data

Answer: A


Q137.  - (Topic 3)

Which of the following represents the BEST method for obtaining business unit acceptance of security controls within an organization?

A. Allow the business units to decide which controls apply to their systems, such as the encryption of sensitive data

B. Create separate controls for the business units based on the types of business and functions they perform

C. Ensure business units are involved in the creation of controls and defining conditions under which they must be applied

D. Provide the business units with control mandates and schedules of audits for compliance validation

Answer: C

Topic 4, Information Security Core Competencies


Q138.  - (Topic 2)

Which of the following BEST describes an international standard framework that is based on the security model Information Technology—Code of Practice for Information Security Management?

A. International Organization for Standardization 27001

B. National Institute of Standards and Technology Special Publication SP 800-12

C. Request For Comment 2196

D. National Institute of Standards and Technology Special Publication SP 800-26

Answer: A


Q139.  - (Topic 3)

Knowing the potential financial loss an organization is willing to suffer if a system fails is a determination of which of the following?

A. Cost benefit

B. Risk appetite

C. Business continuity

D. Likelihood of impact

Answer:: B


Q140.  - (Topic 2)

A new CISO just started with a company and on the CISO's desk is the last complete Information Security Management audit report. The audit report is over two years old. After reading it, what should be the CISO's FIRST priority?

A. Have internal audit conduct another audit to see what has changed.

B. Contract with an external audit company to conduct an unbiased audit

C. Review the recommendations and follow up to see if audit implemented the changes

D. Meet with audit team to determine a timeline for corrections

Answer: C


Q141.  - (Topic 4)

A customer of a bank has placed a dispute on a payment for a credit card account. The banking system uses digital signatures to safeguard the integrity of their transactions. The bank claims that the system shows proof that the customer in fact made the payment. What is this system capability commonly known as?

A. non-repudiation

B. conflict resolution

C. strong authentication

D. digital rights management

Answer: A


Q142.  - (Topic 4)

One of your executives needs to send an important and confidential email. You want to ensure that the message cannot be read by anyone but the recipient. Which of the following keys should be used to encrypt the message?

A. Your public key

B. The recipient's private key

C. The recipient's public key

D. Certificate authority key

Answer: C


Q143. - (Topic 1)

Which of the following are the MOST important factors for proactively determining system vulnerabilities?

A. Subscribe to vendor mailing list to get notification of system vulnerabilities

B. Deploy Intrusion Detection System (IDS) and install anti-virus on systems

C. Configure firewall, perimeter router and Intrusion Prevention System (IPS)

D. Conduct security testing, vulnerability scanning, and penetration testing

Answer: D


Q144.  - (Topic 3)

Which of the following methodologies references the recommended industry standard that Information security project managers should follow?

A. The Security Systems Development Life Cycle

B. The Security Project And Management Methodology

C. Project Management System Methodology

D. Project Management Body of Knowledge

Answer: D


Q145.  - (Topic 1)

When choosing a risk mitigation method what is the MOST important factor?

A. Approval from the board of directors

B. Cost of the mitigation is less than the risk

C. Metrics of mitigation method success

D. Mitigation method complies with PCI regulations

Answer: B


Q146.  - (Topic 3)

This occurs when the quantity or quality of project deliverables is expanded from the original project plan.

A. Scope creep

B. Deadline extension

C. Scope modification

D. Deliverable expansion

Answer: A


Q147.  - (Topic 1)

What is the MAIN reason for conflicts between Information Technology and Information Security programs?

A. Technology governance defines technology policies and standards while security governance does not.

B. Security governance defines technology best practices and Information Technology governance does not.

C. Technology Governance is focused on process risks whereas Security Governance is focused on business risk.

A. D. The effective implementation of security controls can be viewed as an inhibitor to rapid Information Technology implementations.

Answer: D


Q148.  - (Topic 2)

An employee successfully avoids becoming a victim of a sophisticated spear phishing attack due to knowledge gained through the corporate information security awareness program. What type of control has been effectively utilized?

A. Management Control

B. Technical Control

C. Training Control

D. Operational Control

Answer: D


Q149.  - (Topic 1)

Who in the organization determines access to information?

A. Legal department

B. Compliance officer

C. Data Owner

D. Information security officer

Answer: C


Q150.  - (Topic 5)

Access Control lists (ACLs), Firewalls, and Intrusion Prevention Systems are examples of

A. Network based security preventative controls

B. Software segmentation controls

C. Network based security detective controls

D. User segmentation controls

Answer: A