
512-50 PDF Dumps 2022 Exam Questions with Practice Test
Dumps for Free 512-50 Practice Exam Questions
NEW QUESTION 177
Which type of scan is used on the eye to measure the layer of blood vessels?
- A. Iris scan
- B. Signature kinetics scan
- C. Facial recognition scan
- D. Retinal scan
Answer: D
NEW QUESTION 178
The total cost of security controls should:
- A. Be less than the value of the information resource being protected
- B. Should not matter, as long as the information resource is protected
- C. Be greater than the value of the information resource being protected
- D. Be equal to the value of the information resource being protected
Answer: A
NEW QUESTION 179
A recent audit has identified a few control exceptions and is recommending the implementation of technology and processes to address the finding. Which of the following is the MOST likely reason for the organization to reject the implementation of the recommended technology and processes?
- A. The CIO of the organization disagrees with the finding
- B. The organization has purchased cyber insurance
- C. The risk tolerance of the organization permits this risk
- D. The auditors have not followed proper auditing processes
Answer: C
NEW QUESTION 180
In which of the following cases, would an organization be more prone to risk acceptance vs. risk mitigation?
- A. The organization uses exclusively a qualitative process to measure risk
- B. The organization uses exclusively a quantitative process to measure risk
- C. The organization's risk tolerance is high
- D. The organization's risk tolerance is lo
Answer: C
NEW QUESTION 181
Which of the following is a benefit of information security governance?
- A. Reduction of the potential for civil and legal liability
- B. Direct involvement of senior management in developing control processes
- C. Questioning the trust in vendor relationships.
- D. Increasing the risk of decisions based on incomplete management information.
Answer: A
NEW QUESTION 182
When gathering security requirements for an automated business process improvement program, which of the following is MOST important?
- A. Type of encryption required for the data once it is at rest
- B. Type of connection/protocol used to transfer the data
- C. Type of data contained in the process/system
- D. Type of computer the data is processed on
Answer: C
NEW QUESTION 183
Which of the following is used to establish and maintain a framework to provide assurance that information security strategies are aligned with organizational objectives?
- A. Management
- B. Compliance
- C. Awareness
- D. Governance
Answer: D
NEW QUESTION 184
SCENARIO: Critical servers show signs of erratic behavior within your organization's intranet. Initial information indicates the systems are under attack from an outside entity. As the Chief Information Security Officer (CISO), you decide to deploy the Incident Response Team (IRT) to determine the details of this incident and take action according to the information available to the team.
In what phase of the response will the team extract information from the affected systems without altering original data?
- A. Response
- B. Follow-up
- C. Investigation
- D. Recovery
Answer: C
NEW QUESTION 185
In MOST organizations which group periodically reviews network intrusion detection system logs for all systems as part of their daily tasks?
- A. Database Administration
- B. Internal Audit
- C. Information Security
- D. Compliance
Answer: C
NEW QUESTION 186
Who is responsible for verifying that audit directives are implemented?
- A. BOD Audit Committee
- B. IT Management
- C. IT Security
- D. Internal Audit
Answer: D
Explanation:
Reference: https://www.eccouncil.org/information-security-management/
NEW QUESTION 187
A newly-hired CISO needs to understand the organization's financial management standards for business units and operations. Which of the following would be the best source of this information?
- A. The Chief Financial Officer (CFO)
- B. The managers of the accounts payables and accounts receivables teams
- C. The internal accounting department
- D. The external financial audit service
Answer: B
NEW QUESTION 188
SQL injection is a very popular and successful injection attack method. Identify the basic SQL injection text:
- A. NOPS
- B. "DROPTABLE USERNAME"
- C. ' o 1=1 - -
- D. /../../../../
Answer: C
NEW QUESTION 189
How often should the SSAE16 report of your vendors be reviewed?
- A. Annually
- B. Semi-annually
- C. Bi-annually
- D. Quarterly
Answer: A
NEW QUESTION 190
Where does bottom-up financial planning primarily gain information for creating budgets?
- A. By adding all planned operational expenses per quarter then summarizing them in a budget request
- B. By adding all capital and operational costs from the prior budgetary cycle, and determining potential financial shortages
- C. By reviewing last year's program-level costs and adding a percentage of expected additional portfolio costs
- D. By adding the cost of all known individual tasks and projects that are planned for the next budgetary cycle
Answer: A
NEW QUESTION 191
A newly appointed security officer finds data leakage software licenses that had never been used. The officer decides to implement a project to ensure it gets installed, but the project gets a great deal of resistance across the organization. Which of the following represents the MOST likely reason for this situation?
- A. The project was initiated without an effort to get support from impacted business units in the organization
- B. The software license expiration is probably out of synchronization with other software licenses
- C. The software is out of date and does not provide for a scalable solution across the enterprise
- D. The security officer should allow time for the organization to get accustomed to her presence before initiating security projects
Answer: A
NEW QUESTION 192
The Security Operations Center (SOC) just purchased a new intrusion prevention system (IPS) that needs to be deployed in-line for best defense. The IT group is concerned about putting the new IPS in-line because it might negatively impact network availability. What would be the BEST approach for the CISO to reassure the IT group?
- A. Explain to the IT group that the IPS will fail open once in-line however it will be deployed in monitor mode for a set period of time to ensure that it doesn't block any legitimate traffic
- B. Explain to the IT group that the IPS won't cause any network impact because it will fail open
- C. Work with the IT group and tell them to put IPS in-line and say it won't cause any network impact
- D. Explain to the IT group that this is a business need and the IPS will fail open however, if there is a network failure the CISO will accept responsibility
Answer: A
NEW QUESTION 193
SCENARIO: Critical servers show signs of erratic behavior within your organization's intranet. Initial information indicates the systems are under attack from an outside entity. As the Chief Information Security Officer (CISO), you decide to deploy the Incident Response Team (IRT) to determine the details of this incident and take action according to the information available to the team.
In what phase of the response will the team extract information from the affected systems without altering original data?
- A. Response
- B. Follow-up
- C. Investigation
- D. Recovery
Answer: C
Explanation:
Explanation
Scenario4
NEW QUESTION 194
Which of the following methodologies references the recommended industry standard that Information security project managers should follow?
- A. Project Management Body of Knowledge
- B. The Security Project And Management Methodology
- C. The Security Systems Development Life Cycle
- D. Project Management System Methodology
Answer: A
NEW QUESTION 195
An organization has defined a set of standard security controls. This organization has also defined the circumstances and conditions in which they must be applied. What is the NEXT logical step in applying the controls in the organization?
- A. Perform an asset classification
- B. Determine the risk tolerance
- C. Create an architecture gap analysis
- D. Analyze existing controls on systems
Answer: A
NEW QUESTION 196
Which of the following should be determined while defining risk management strategies?
- A. IT architecture complexity
- B. Enterprise disaster recovery plans
- C. Organizational objectives and risk tolerance
- D. Risk assessment criteria
Answer: C
NEW QUESTION 197
Which of the following is the MOST important reason for performing assessments of the security portfolio?
- A. To create executive support of the portfolio
- B. To discover new technologies and processes for implementation within the portfolio
- C. To provide independent 3rd party reviews of security effectiveness
- D. To assure that the portfolio is aligned to the needs of the broader organization
Answer: D
NEW QUESTION 198
......
Check your preparation for EC-COUNCIL 512-50 On-Demand Exam: https://pass4sure.verifieddumps.com/512-50-valid-exam-braindumps.html
