512-50 PDF Dumps 2022 Exam Questions with Practice Test [Q177-Q198]

Share

512-50 PDF Dumps 2022 Exam Questions with Practice Test

Dumps for Free 512-50 Practice Exam Questions

NEW QUESTION 177
Which type of scan is used on the eye to measure the layer of blood vessels?

  • A. Iris scan
  • B. Signature kinetics scan
  • C. Facial recognition scan
  • D. Retinal scan

Answer: D

 

NEW QUESTION 178
The total cost of security controls should:

  • A. Be less than the value of the information resource being protected
  • B. Should not matter, as long as the information resource is protected
  • C. Be greater than the value of the information resource being protected
  • D. Be equal to the value of the information resource being protected

Answer: A

 

NEW QUESTION 179
A recent audit has identified a few control exceptions and is recommending the implementation of technology and processes to address the finding. Which of the following is the MOST likely reason for the organization to reject the implementation of the recommended technology and processes?

  • A. The CIO of the organization disagrees with the finding
  • B. The organization has purchased cyber insurance
  • C. The risk tolerance of the organization permits this risk
  • D. The auditors have not followed proper auditing processes

Answer: C

 

NEW QUESTION 180
In which of the following cases, would an organization be more prone to risk acceptance vs. risk mitigation?

  • A. The organization uses exclusively a qualitative process to measure risk
  • B. The organization uses exclusively a quantitative process to measure risk
  • C. The organization's risk tolerance is high
  • D. The organization's risk tolerance is lo

Answer: C

 

NEW QUESTION 181
Which of the following is a benefit of information security governance?

  • A. Reduction of the potential for civil and legal liability
  • B. Direct involvement of senior management in developing control processes
  • C. Questioning the trust in vendor relationships.
  • D. Increasing the risk of decisions based on incomplete management information.

Answer: A

 

NEW QUESTION 182
When gathering security requirements for an automated business process improvement program, which of the following is MOST important?

  • A. Type of encryption required for the data once it is at rest
  • B. Type of connection/protocol used to transfer the data
  • C. Type of data contained in the process/system
  • D. Type of computer the data is processed on

Answer: C

 

NEW QUESTION 183
Which of the following is used to establish and maintain a framework to provide assurance that information security strategies are aligned with organizational objectives?

  • A. Management
  • B. Compliance
  • C. Awareness
  • D. Governance

Answer: D

 

NEW QUESTION 184
SCENARIO: Critical servers show signs of erratic behavior within your organization's intranet. Initial information indicates the systems are under attack from an outside entity. As the Chief Information Security Officer (CISO), you decide to deploy the Incident Response Team (IRT) to determine the details of this incident and take action according to the information available to the team.
In what phase of the response will the team extract information from the affected systems without altering original data?

  • A. Response
  • B. Follow-up
  • C. Investigation
  • D. Recovery

Answer: C

 

NEW QUESTION 185
In MOST organizations which group periodically reviews network intrusion detection system logs for all systems as part of their daily tasks?

  • A. Database Administration
  • B. Internal Audit
  • C. Information Security
  • D. Compliance

Answer: C

 

NEW QUESTION 186
Who is responsible for verifying that audit directives are implemented?

  • A. BOD Audit Committee
  • B. IT Management
  • C. IT Security
  • D. Internal Audit

Answer: D

Explanation:
Reference: https://www.eccouncil.org/information-security-management/

 

NEW QUESTION 187
A newly-hired CISO needs to understand the organization's financial management standards for business units and operations. Which of the following would be the best source of this information?

  • A. The Chief Financial Officer (CFO)
  • B. The managers of the accounts payables and accounts receivables teams
  • C. The internal accounting department
  • D. The external financial audit service

Answer: B

 

NEW QUESTION 188
SQL injection is a very popular and successful injection attack method. Identify the basic SQL injection text:

  • A. NOPS
  • B. "DROPTABLE USERNAME"
  • C. ' o 1=1 - -
  • D. /../../../../

Answer: C

 

NEW QUESTION 189
How often should the SSAE16 report of your vendors be reviewed?

  • A. Annually
  • B. Semi-annually
  • C. Bi-annually
  • D. Quarterly

Answer: A

 

NEW QUESTION 190
Where does bottom-up financial planning primarily gain information for creating budgets?

  • A. By adding all planned operational expenses per quarter then summarizing them in a budget request
  • B. By adding all capital and operational costs from the prior budgetary cycle, and determining potential financial shortages
  • C. By reviewing last year's program-level costs and adding a percentage of expected additional portfolio costs
  • D. By adding the cost of all known individual tasks and projects that are planned for the next budgetary cycle

Answer: A

 

NEW QUESTION 191
A newly appointed security officer finds data leakage software licenses that had never been used. The officer decides to implement a project to ensure it gets installed, but the project gets a great deal of resistance across the organization. Which of the following represents the MOST likely reason for this situation?

  • A. The project was initiated without an effort to get support from impacted business units in the organization
  • B. The software license expiration is probably out of synchronization with other software licenses
  • C. The software is out of date and does not provide for a scalable solution across the enterprise
  • D. The security officer should allow time for the organization to get accustomed to her presence before initiating security projects

Answer: A

 

NEW QUESTION 192
The Security Operations Center (SOC) just purchased a new intrusion prevention system (IPS) that needs to be deployed in-line for best defense. The IT group is concerned about putting the new IPS in-line because it might negatively impact network availability. What would be the BEST approach for the CISO to reassure the IT group?

  • A. Explain to the IT group that the IPS will fail open once in-line however it will be deployed in monitor mode for a set period of time to ensure that it doesn't block any legitimate traffic
  • B. Explain to the IT group that the IPS won't cause any network impact because it will fail open
  • C. Work with the IT group and tell them to put IPS in-line and say it won't cause any network impact
  • D. Explain to the IT group that this is a business need and the IPS will fail open however, if there is a network failure the CISO will accept responsibility

Answer: A

 

NEW QUESTION 193
SCENARIO: Critical servers show signs of erratic behavior within your organization's intranet. Initial information indicates the systems are under attack from an outside entity. As the Chief Information Security Officer (CISO), you decide to deploy the Incident Response Team (IRT) to determine the details of this incident and take action according to the information available to the team.
In what phase of the response will the team extract information from the affected systems without altering original data?

  • A. Response
  • B. Follow-up
  • C. Investigation
  • D. Recovery

Answer: C

Explanation:
Explanation
Scenario4

 

NEW QUESTION 194
Which of the following methodologies references the recommended industry standard that Information security project managers should follow?

  • A. Project Management Body of Knowledge
  • B. The Security Project And Management Methodology
  • C. The Security Systems Development Life Cycle
  • D. Project Management System Methodology

Answer: A

 

NEW QUESTION 195
An organization has defined a set of standard security controls. This organization has also defined the circumstances and conditions in which they must be applied. What is the NEXT logical step in applying the controls in the organization?

  • A. Perform an asset classification
  • B. Determine the risk tolerance
  • C. Create an architecture gap analysis
  • D. Analyze existing controls on systems

Answer: A

 

NEW QUESTION 196
Which of the following should be determined while defining risk management strategies?

  • A. IT architecture complexity
  • B. Enterprise disaster recovery plans
  • C. Organizational objectives and risk tolerance
  • D. Risk assessment criteria

Answer: C

 

NEW QUESTION 197
Which of the following is the MOST important reason for performing assessments of the security portfolio?

  • A. To create executive support of the portfolio
  • B. To discover new technologies and processes for implementation within the portfolio
  • C. To provide independent 3rd party reviews of security effectiveness
  • D. To assure that the portfolio is aligned to the needs of the broader organization

Answer: D

 

NEW QUESTION 198
......

Check your preparation for EC-COUNCIL 512-50 On-Demand Exam: https://pass4sure.verifieddumps.com/512-50-valid-exam-braindumps.html