Proper study guides for Renovate EC-Council EC-Council Certified CISO (CCISO) certified begins with EC-Council 712-50 preparation products which designed to deliver the Virtual 712-50 questions by making you pass the 712-50 test at your first time. Try the free 712-50 demo right now.

Q16.  - (Topic 5)

As the CISO you need to write the IT security strategic plan. Which of the following is the MOST important to review before you start writing the plan?

A. The existing IT environment.

B. The company business plan.

C. The present IT budget.

D. Other corporate technology trends.

Answer: B


Q17.  - (Topic 5)

The Annualized Loss Expectancy (Before) minus Annualized Loss Expectancy (After) minus Annual Safeguard Cost is the formula for determining:

A. Safeguard Value

B. Cost Benefit Analysis

C. Single Loss Expectancy

D. Life Cycle Loss Expectancy

Answer: B


Q18.  - (Topic 5)

Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate controls. You assign work to your staff to create or adjust existing security controls to ensure they are adequate for risk mitigation needs.

When adjusting the controls to mitigate the risks, how often should the CISO perform an audit to verify the controls?

A. Annually

B. Semi-annually

C. Quarterly

D. Never

Answer: D


Q19.  - (Topic 4)

Which of the following is a countermeasure to prevent unauthorized database access from web applications?

A. Session encryption

B. Removing all stored procedures

C. Input sanitization

D. Library control

Answer: C


Q20.  - (Topic 1)

Which of the following is a weakness of an asset or group of assets that can be exploited by one or more threats?

A. Threat

B. Vulnerability

C. Attack vector

A. D. Exploitation

Answer: B


Q21.  - (Topic 3)

Which of the following are not stakeholders of IT security projects?

A. Board of directors

B. Third party vendors

C. CISO

D. Help Desk

Answer: B


Q22.  - (Topic 5)

Human resource planning for security professionals in your organization is a:

A. Simple and easy task because the threats are getting easier to find and correct.

B. Training requirement that is met through once every year user training.

C. Training requirement that is on-going and always changing.

D. Not needed because automation and anti-virus software has eliminated the threats.

Answer: C


Q23.  - (Topic 5)

Which of the following conditions would be the MOST probable reason for a security project to be rejected by the executive board of an organization?

A. The Net Present Value (NPV) of the project is positive

B. The NPV of the project is negative

C. The Return on Investment (ROI) is larger than 10 months

D. The ROI is lower than 10 months

Answer: B


Q24.  - (Topic 3)

Your incident response plan should include which of the following?

A. Procedures for litigation

B. Procedures for reclamation

C. Procedures for classification

D. Procedures for charge-back

Answer: C


Q25.  - (Topic 5)

When analyzing and forecasting an operating expense budget what are not included?

A. Software and hardware license fees

B. Utilities and power costs

C. Network connectivity costs

D. New datacenter to operate from

Answer: D


Q26.  - (Topic 5)

When creating contractual agreements and procurement processes why should security requirements be included?

A. To make sure they are added on after the process is completed

B. To make sure the costs of security is included and understood

C. To make sure the security process aligns with the vendor’s security process

D. To make sure the patching process is included with the costs

Answer: B


Q27.  - (Topic 1)

Which of the following has the GREATEST impact on the implementation of an information security governance model?

A. Organizational budget

B. Distance between physical locations

C. Number of employees

D. Complexity of organizational structure

Answer: D


Q28.  - (Topic 3)

A severe security threat has been detected on your corporate network. As CISO you quickly assemble key members of the Information Technology team and business operations to determine a modification to security controls in response to the threat. This is an example of:

A. Change management

B. Business continuity planning

C. Security Incident Response

D. Thought leadership

Answer: C


Q29.  - (Topic 1)

Which of the following is the MOST important benefit of an effective security governance process?

A. Reduction of liability and overall risk to the organization

B. Better vendor management

C. Reduction of security breaches

D. Senior management participation in the incident response process

Answer: A


Q30.  - (Topic 5)

Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined security policy and framework for their Information Security Program. Your new boss, the Chief Financial Officer, has asked you to draft an outline of a security policy and recommend an industry/sector neutral information security control framework for implementation.

Which of the following industry / sector neutral information security control frameworks should you recommend for implementation?

A. National Institute of Standards and Technology (NIST) Special Publication 800-53

B. Payment Card Industry Digital Security Standard (PCI DSS)

C. International Organization for Standardization – ISO 27001/2

D. British Standard 7799 (BS7799)

Answer: C