
Get instant access to 712-50 Practice Tests 2021 Free Updated Today!
Welcome to download the newest PassLeader 712-50 PDF dumps ( 396 Q&As)
NEW QUESTION 156
This occurs when the quantity or quality of project deliverables is expanded from the original project plan.
- A. Deadline extension
- B. Deliverable expansion
- C. Scope modification
- D. Scope creep
Answer: D
NEW QUESTION 157
IT control objectives are useful to IT auditors as they provide the basis for understanding the:
- A. Techniques for securing information.
- B. Desired results or purpose of implementing specific control procedures.
- C. The audit control checklist.
- D. Security policy
Answer: B
NEW QUESTION 158
Scenario: As you begin to develop the program for your organization, you assess the corporate culture and determine that there is a pervasive opinion that the security program only slows things down and limits the performance of the "real workers."
Which group of people should be consulted when developing your security program?
- A. All of the above
- B. Peers
- C. End Users
- D. Executive Management
Answer: A
NEW QUESTION 159
Which of the following are necessary to formulate responses to external audit findings?
- A. Technical Staff, Budget Authority, Management
- B. Internal Audit, Management, and Technical Staff
- C. Internal Audit, Budget Authority, Management
- D. Technical Staff, Internal Audit, Budget Authority
Answer: A
NEW QUESTION 160
A recommended method to document the respective roles of groups and individuals for a given process is to:
- A. Develop a Responsible, Accountable, Consulted, Informed (RACI) chart
- B. Develop an isolinear response matrix with cost benefit analysis projections
- C. Develop a detailed internal organization chart
- D. Develop a telephone call tree for emergency response
Answer: A
NEW QUESTION 161
You are having a penetration test done on your company network and the leader of the team says they discovered all the network devices because no one had changed the Simple Network Management Protocol (SNMP) community strings from the defaults.
Which of the following is a default community string?
- A. Execute
- B. Administrator
- C. Public
- D. Read
Answer: C
NEW QUESTION 162
What is the primary reason for performing vendor management?
- A. To understand the risk coverage that are being mitigated by the vendor
- B. To define the partnership for long-term success
- C. To establish a vendor selection process
- D. To document the relationship between the company and the vendor
Answer: A
NEW QUESTION 163
Which of the following are primary concerns for management with regard to assessing internal control objectives?
- A. Communication, Reliability, Cost
- B. Confidentiality, Compliance, Cost
- C. Compliance, Effectiveness, Efficiency
- D. Confidentiality, Availability, Integrity
Answer: C
NEW QUESTION 164
Providing oversight of a comprehensive information security program for the entire organization is the primary responsibility of which group under the InfoSec governance framework?
- A. All employees and users
- B. Senior Executives
- C. Office of the Auditor
- D. Office of the General Counsel
Answer: B
NEW QUESTION 165
SQL injection is a very popular and successful injection attack method. Identify the basic SQL injection text:
- A. NOPS
- B. 'O 1=1 - -
- C. "DROPTABLE USERNAME"
- D. /../../../../
Answer: B
NEW QUESTION 166
Scenario: The new CISO was informed of all the Information Security projects that the section has in progress. Two projects are over a year behind schedule and way over budget.
Using the best business practices for project management, you determine that the project
correctly aligns with the organization goals. What should be verified next?
- A. Resources
- B. Budget
- C. Constraints
- D. Scope
Answer: D
NEW QUESTION 167
Regulatory requirements typically force organizations to implement ____________.
- A. Optional controls
- B. Discretionary controls
- C. Mandatory controls
- D. Financial controls
Answer: C
NEW QUESTION 168
Which of the following activities is the MAIN purpose of the risk assessment process?
- A. Calculating the risks to which assets are exposed in their current setting
- B. Assigning value to each information asset
- C. Classifying and organizing information assets into meaningful groups
- D. Creating an inventory of information assets
Answer: A
NEW QUESTION 169
When selecting a security solution with reoccurring maintenance costs after the first year (choose the BEST answer):
- A. Defer selection until the market improves and cash flow is positive
- B. The CISO should cut other essential programs to ensure the new solution's continued use
- C. Implement the solution and ask for the increased operating cost budget when it is time
- D. Communicate future operating costs to the CIO/CFO and seek commitment from them to ensure the new solution's continued use
Answer: D
NEW QUESTION 170
A CISO sees abnormally high volumes of exceptions to security requirements and constant pressure from business units to change security processes. Which of the following represents the MOST LIKELY cause of this situation?
- A. This is normal since business units typically resist security requirements
- B. Poor audit support for the security program
- C. A lack of executive presence within the security program
- D. Poor alignment of the security program to business needs
Answer: D
NEW QUESTION 171
Which of the following is the MAIN reason to follow a formal risk management process in an organization that hosts and uses privately identifiable information (PII) as part of their business models and processes?
- A. Need to transfer the risk associated with hosting PII data
- B. Fiduciary responsibility to safeguard credit information
- C. Need to comply with breach disclosure laws
- D. Need to better understand the risk associated with using PII data
Answer: D
NEW QUESTION 172
The effectiveness of social engineering penetration testing using phishing can be used as a Key Performance Indicator (KPI) for the effectiveness of an organization's
- A. Identity and Access Management Program.
- B. Risk Management Program.
- C. Security Awareness Program.
- D. Anti-Spam controls.
Answer: C
NEW QUESTION 173
Which of the following illustrates an operational control process:
- A. Establishing procurement standards for cloud vendors
- B. Classifying an information system as part of a risk assessment
- C. Installing an appropriate fire suppression system in the data center
- D. Conducting an audit of the configuration management process
Answer: C
NEW QUESTION 174
Why is it vitally important that senior management endorse a security policy?
- A. So that external bodies will recognize the organizations commitment to security.
- B. So that employees will follow the policy directives.
- C. So that they will accept ownership for security within the organization.
- D. So that they can be held legally accountable.
Answer: C
NEW QUESTION 175
Your penetration testing team installs an in-line hardware key logger onto one of your network machines. Which of the following is of major concern to the security organization?
- A. In-line hardware keyloggers don't require physical access
- B. In-line hardware keyloggers are relatively inexpensive
- C. In-line hardware keyloggers are undetectable by software
- D. In-line hardware keyloggers don't comply to industry regulations
Answer: C
NEW QUESTION 176
When gathering security requirements for an automated business process improvement program, which of the following is MOST important?
- A. Type of encryption required for the data once it is at rest
- B. Type of computer the data is processed on
- C. Type of connection/protocol used to transfer the data
- D. Type of data contained in the process/system
Answer: D
NEW QUESTION 177
You are just hired as the new CISO and are being briefed on all the Information Security projects that your section has on going. You discover that most projects are behind schedule and over budget.
Using the best business practices for project management you determine that the project correctly aligns with the company goals and the scope of the project is correct. What is the NEXT step?
- A. Verify constraints
- B. Verify resources
- C. Review time schedules
- D. Verify budget
Answer: B
NEW QUESTION 178
During the last decade, what trend has caused the MOST serious issues in relation to physical security?
- A. The internet of Things allows easy compromise of cloud-based systems
- B. Camera systems have become more economical and expanded in their use
- C. Data is more portable due to the increased use of smartphones and tablets
- D. The move from centralized computing to decentralized computing
Answer: C
NEW QUESTION 179
Which of the following is MOST important when tuning an Intrusion Detection System (IDS)?
- A. Storage encryption
- B. Log retention
- C. Type of authentication
- D. Trusted and untrusted networks
Answer: D
NEW QUESTION 180
Which of the following will be MOST helpful for getting an Information Security project that is behind schedule back on schedule?
- A. Upper management support
- B. More training of staff members
- C. More frequent project milestone meetings
- D. Involve internal audit
Answer: A
NEW QUESTION 181
......
Jul-2021 Latest Exam4PDF 712-50 Exam Dumps with PDF and Exam Engine: https://www.exam4pdf.com/712-50-dumps-torrent.html
Premium Quality EC-COUNCIL 712-50 Online dumps: https://drive.google.com/open?id=1eODh5VNVT4MbwUv6rLdTCAfE00Kd6waC

