ExamGecko
Home Home / ECCouncil / 712-50

ECCouncil 712-50 Practice Test - Questions Answers, Page 6

Question list
Search
Search

List of questions

Search

Related questions











A Security Operations Centre (SOC) manager is informed that a database containing highly sensitive corporate strategy information is under attack. Information has been stolen and the database server was disconnected. Who must be informed of this incident?

A.
Internal audit
A.
Internal audit
Answers
B.
The data owner
B.
The data owner
Answers
C.
All executive staff
C.
All executive staff
Answers
D.
Government regulators
D.
Government regulators
Answers
Suggested answer: B

A company wants to fill a Chief Information Security Officer position in the organization. They need to define and implement a more holistic security program. Which of the following qualifications and experience would be MOST desirable to find in a candidate?

A.
Multiple certifications, strong technical capabilities and lengthy resume
A.
Multiple certifications, strong technical capabilities and lengthy resume
Answers
B.
Industry certifications, technical knowledge and program management skills
B.
Industry certifications, technical knowledge and program management skills
Answers
C.
College degree, audit capabilities and complex project management
C.
College degree, audit capabilities and complex project management
Answers
D.
Multiple references, strong background check and industry certifications
D.
Multiple references, strong background check and industry certifications
Answers
Suggested answer: B

An organization licenses and uses personal information for business operations, and a server containing that information has been compromised. What kind of law would require notifying the owner or licensee of this incident?

A.
Data breach disclosure
A.
Data breach disclosure
Answers
B.
Consumer right disclosure
B.
Consumer right disclosure
Answers
C.
Security incident disclosure
C.
Security incident disclosure
Answers
D.
Special circumstance disclosure
D.
Special circumstance disclosure
Answers
Suggested answer: A

An organization's firewall technology needs replaced. A specific technology has been selected that is less costly than others and lacking in some important capabilities. The security officer has voiced concerns about sensitive data breaches but the decision is made to purchase. What does this selection indicate?

A.
A high threat environment
A.
A high threat environment
Answers
B.
A low risk tolerance environment
B.
A low risk tolerance environment
Answers
C.
I low vulnerability environment
C.
I low vulnerability environment
Answers
D.
A high risk tolerance environment
D.
A high risk tolerance environment
Answers
Suggested answer: D

An organization has defined a set of standard security controls. This organization has also defined the circumstances and conditions in which they must be applied. What is the NEXT logical step in applying the controls in the organization?

A.
Determine the risk tolerance
A.
Determine the risk tolerance
Answers
B.
Perform an asset classification
B.
Perform an asset classification
Answers
C.
Create an architecture gap analysis
C.
Create an architecture gap analysis
Answers
D.
Analyze existing controls on systems
D.
Analyze existing controls on systems
Answers
Suggested answer: B

A security manager has created a risk program. Which of the following is a critical part of ensuring the program is successful?

A.
Providing a risk program governance structure
A.
Providing a risk program governance structure
Answers
B.
Ensuring developers include risk control comments in code
B.
Ensuring developers include risk control comments in code
Answers
C.
Creating risk assessment templates based on specific threats
C.
Creating risk assessment templates based on specific threats
Answers
D.
Allowing for the acceptance of risk for regulatory compliance requirements
D.
Allowing for the acceptance of risk for regulatory compliance requirements
Answers
Suggested answer: A

Which of the following international standards can be BEST used to define a Risk Management process in an organization?

A.
National Institute for Standards and Technology 800-50 (NIST 800-50)
A.
National Institute for Standards and Technology 800-50 (NIST 800-50)
Answers
B.
International Organization for Standardizations – 27005 (ISO-27005)
B.
International Organization for Standardizations – 27005 (ISO-27005)
Answers
C.
Payment Card Industry Data Security Standards (PCI-DSS)
C.
Payment Card Industry Data Security Standards (PCI-DSS)
Answers
D.
International Organization for Standardizations – 27004 (ISO-27004)
D.
International Organization for Standardizations – 27004 (ISO-27004)
Answers
Suggested answer: B

An organization is looking for a framework to measure the efficiency and effectiveness of their Information Security Management System. Which of the following international standards can BEST assist this organization?

A.
International Organization for Standardizations – 27004 (ISO-27004)
A.
International Organization for Standardizations – 27004 (ISO-27004)
Answers
B.
Payment Card Industry Data Security Standards (PCI-DSS)
B.
Payment Card Industry Data Security Standards (PCI-DSS)
Answers
C.
Control Objectives for Information Technology (COBIT)
C.
Control Objectives for Information Technology (COBIT)
Answers
D.
International Organization for Standardizations – 27005 (ISO-27005)
D.
International Organization for Standardizations – 27005 (ISO-27005)
Answers
Suggested answer: A

A global retail company is creating a new compliance management process. Which of the following regulations is of MOST importance to be tracked and managed by this process?

A.
Information Technology Infrastructure Library (ITIL)
A.
Information Technology Infrastructure Library (ITIL)
Answers
B.
International Organization for Standardization (ISO) standards
B.
International Organization for Standardization (ISO) standards
Answers
C.
Payment Card Industry Data Security Standards (PCI-DSS)
C.
Payment Card Industry Data Security Standards (PCI-DSS)
Answers
D.
National Institute for Standards and Technology (NIST) standard
D.
National Institute for Standards and Technology (NIST) standard
Answers
Suggested answer: C

A global retail organization is looking to implement a consistent Disaster Recovery and Business Continuity Process across all of its business units. Which of the following standards and guidelines can BEST address this organization's need?

A.
International Organization for Standardizations – 22301 (ISO-22301)
A.
International Organization for Standardizations – 22301 (ISO-22301)
Answers
B.
Information Technology Infrastructure Library (ITIL)
B.
Information Technology Infrastructure Library (ITIL)
Answers
C.
Payment Card Industry Data Security Standards (PCI-DSS)
C.
Payment Card Industry Data Security Standards (PCI-DSS)
Answers
D.
International Organization for Standardizations – 27005 (ISO-27005)
D.
International Organization for Standardizations – 27005 (ISO-27005)
Answers
Suggested answer: A
Total 460 questions
Go to page: of 46