Our pass rate is high to 98.9% and the similarity percentage between our 712-50 study guide and real exam is 90% based on our seven-year educating experience. Do you want achievements in the EC-Council 712-50 exam in just one try? I am currently studying for the EC-Council 712-50 exam. Latest EC-Council 712-50 Test exam practice questions and answers, Try EC-Council 712-50 Brain Dumps First.
Q1. - (Topic 2)
Which of the following represents the BEST reason for an organization to use the Control Objectives for Information and Related Technology (COBIT) as an Information Technology (IT) framework?
A. It allows executives to more effectively monitor IT implementation costs
B. Implementation of it eases an organization’s auditing and compliance burden
C. Information Security (IS) procedures often require augmentation with other standards
A. D. It provides for a consistent and repeatable staffing model for technology organizations
Answer: B
Q2. - (Topic 1)
Within an organization’s vulnerability management program, who has the responsibility to implement remediation actions?
A. Security officer
B. Data owner
A. C. Vulnerability engineer
D. System administrator
Answer: D
Q3. - (Topic 5)
What is the primary reason for performing a return on investment analysis?
A. To decide between multiple vendors
B. To decide is the solution costs less than the risk it is mitigating
C. To determine the current present value of a project
D. To determine the annual rate of loss
Answer: B
Q4. - (Topic 4)
Which of the following is the MAIN security concern for public cloud computing?
A. Unable to control physical access to the servers
B. Unable to track log on activity
C. Unable to run anti-virus scans
D. Unable to patch systems as needed
Answer: A
Q5. - (Topic 5)
What is the BEST reason for having a formal request for proposal process?
A. Creates a timeline for purchasing and budgeting
B. Allows small companies to compete with larger companies
C. Clearly identifies risks and benefits before funding is spent
D. Informs suppliers a company is going to make a purchase
Answer: C
Q6. - (Topic 3)
A recommended method to document the respective roles of groups and individuals for a given process is to:
A. Develop a detailed internal organization chart
B. Develop a telephone call tree for emergency response
C. Develop an isolinear response matrix with cost benefit analysis projections
D. Develop a Responsible, Accountable, Consulted, Informed (RACI) chart
Answer: D
Q7. - (Topic 2)
Which of the following best describes the purpose of the International Organization for Standardization (ISO) 27002 standard?
A. To give information security management recommendations to those who are responsible for initiating, implementing, or maintaining security in their organization.
B. To provide a common basis for developing organizational security standards
C. To provide effective security management practice and to provide confidence in inter- organizational dealings
D. To established guidelines and general principles for initiating, implementing, maintaining, and improving information security management within an organization
Answer: D
Q8. - (Topic 1)
Ensuring that the actions of a set of people, applications and systems follow the organization’s rules is BEST described as:
A. Risk management
B. Security management
C. Mitigation management
D. Compliance management
Answer: D
Q9. - (Topic 1)
When dealing with a risk management process, asset classification is important because it will impact the overall:
A. Threat identification
B. Risk monitoring
C. Risk treatment
D. Risk tolerance
Answer: C
Q10. - (Topic 5)
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used as audit baselines. The audit report was presented to the CISO and a variety of high, medium and low rated gaps were identified.
Which of the following is the FIRST action the CISO will perform after receiving the audit report?
A. Inform peer executives of the audit results
B. Validate gaps and accept or dispute the audit findings
C. Create remediation plans to address program gaps
D. Determine if security policies and procedures are adequate
Answer: B
Q11. - (Topic 2)
How often should an environment be monitored for cyber threats, risks, and exposures?
A. Weekly
B. Monthly
C. Quarterly
D. Daily
Answer: D
Q12. - (Topic 5)
Scenario: As you begin to develop the program for your organization, you assess the corporate culture and determine that there is a pervasive opinion that the security program only slows things down and limits the performance of the “real workers.”
What must you do first in order to shift the prevailing opinion and reshape corporate culture to understand the value of information security to the organization?
A. Cite compliance with laws, statutes, and regulations – explaining the financial implications for the company for non-compliance
B. Understand the business and focus your efforts on enabling operations securely
C. Draw from your experience and recount stories of how other companies have been compromised
D. Cite corporate policy and insist on compliance with audit findings
Answer: B
Q13. - (Topic 1)
An organization has defined a set of standard security controls. This organization has also defined the circumstances and conditions in which they must be applied. What is the NEXT logical step in applying the controls in the organization?
A. Determine the risk tolerance
B. Perform an asset classification
C. Create an architecture gap analysis
D. Analyze existing controls on systems
Answer: B
Q14. - (Topic 3)
Which of the following is critical in creating a security program aligned with an organization’s goals?
A. Ensure security budgets enable technical acquisition and resource allocation based on internal compliance requirements
B. Develop a culture in which users, managers and IT professionals all make good decisions about information risk
C. Provide clear communication of security program support requirements and audit schedules
A. D. Create security awareness programs that include clear definition of security program goals and charters
Answer: B
Q15. - (Topic 1)
What is the main purpose of the Incident Response Team?
A. Ensure efficient recovery and reinstate repaired systems
B. Create effective policies detailing program activities
A. C. Communicate details of information security incidents
D. Provide current employee awareness programs
Answer: A