Which of the following functions MUST your Information Security Governance program include for formal organizational reporting?
Reveal answer details Close answer details
Correct answerA
EC-COUNCIL · 512-50
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Single choice
Which of the following functions MUST your Information Security Governance program include for formal organizational reporting? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following defines the boundaries and scope of a risk assessment? Reveal answer details Close answer detailsCorrect answerB Explanation References:
Single choice
A security manager regularly checks work areas after business hours for security violations; such as unsecured files or unattended computers with active sessions. Reveal answer details Close answer detailsCorrect answerC
Single choice
An organization licenses and uses personal information for business operations, and a server containing that information has been compromised. What kind of law would require notifying the owner or licensee of this incident? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following most commonly falls within the scope of an information security governance steering committee? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following is true regarding expenditures? Reveal answer details Close answer detailsCorrect answerD
Single choice
You are just hired as the new CISO and are being briefed on all the Information Security projects that your section has on going. You discover that most projects are behind schedule and over budget. Using the best business practices for project management you determine that the project correct aligns with the company goals. What needs to be verified FIRST? Reveal answer details Close answer detailsCorrect answerA
Single choice
Annual Loss Expectancy is derived from the function of which two factors? Reveal answer details Close answer detailsCorrect answerD
Single choice
The PRIMARY objective for information security program development should be: Reveal answer details Close answer detailsCorrect answerA
Single choice
In effort to save your company money which of the following methods of training results in the lowest cost for the organization? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following is a symmetric encryption algorithm? Reveal answer details Close answer detailsCorrect answerA
Single choice
Scenario: Your corporate systems have been under constant probing and attack from foreign IP addresses for more than a week. Your security team and security infrastructure have performed well under the stress. access to the data on the foreign server. What action should you take FIRST? Reveal answer details Close answer detailsCorrect answerC
Single choice
What is the MAIN reason for conflicts between Information Technology and Information Security programs? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following provides an audit framework? Reveal answer details Close answer detailsCorrect answerA
Single choice
The process for management approval of the security certification process which states the risks and mitigation of such risks of a given IT system is called Reveal answer details Close answer detailsCorrect answerC
Single choice
Your incident handling manager detects a virus attack in the network of your company. You develop a signature based on the characteristics of the detected virus. Which of the following phases in the incident handling process will utilize the signature to resolve this incident? Reveal answer details Close answer detailsCorrect answerD
Single choice
Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small retail merchant but it is expected to grow to a global customer base of many millions of customers in just a few years. This global retail company is expected to accept credit card payments. Which of the following is of MOST concern when defining a security program for this organization? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following will be MOST helpful for getting an Information Security project that is behind schedule back on schedule? Reveal answer details Close answer detailsCorrect answerA
Single choice
Scenario: An organization has recently appointed a CISO. This is a new role in the organization and it signals the increasing need to address security consistently at the enterprise level. This new CISO, while confident with skills and experience, is constantly on the defensive and is unable to advance the IT security centric agenda. The CISO has been able to implement a number of technical controls and is able to influence the Information Technology teams but has not been able to influence the rest of the organization. Reveal answer details Close answer detailsCorrect answerB
Single choice
Scenario: As you begin to develop the program for your organization, you assess the corporate culture and determine that there is a pervasive opinion that the security program only slows things down and limits the performance of the "real workers." What must you do first in order to shift the prevailing opinion and reshape corporate culture to understand the value of information security to the organization? Reveal answer details Close answer detailsCorrect answerB
Single choice
When creating a vulnerability scan schedule, who is the MOST critical person to communicate with in order to ensure impact of the scan is minimized? Reveal answer details Close answer detailsCorrect answerA
Single choice
In which of the following cases, would an organization be more prone to risk acceptance vs. Reveal answer details Close answer detailsCorrect answerC
Single choice
The new CISO was informed of all the Information Security projects that the organization has in progress. Which of the following needs to be performed NEXT? Reveal answer details Close answer detailsCorrect answerA
Single choice
The company decides to release the application without remediating the high-risk vulnerabilities. Which of the following is the MOST likely reason for the company to release the application? Reveal answer details Close answer detailsCorrect answerC
Single choice
As the CISO for your company you are accountable for the protection of information resources commensurate with: Reveal answer details Close answer detailsCorrect answerD
Single choice
Security related breaches are assessed and contained through which of the following? Reveal answer details Close answer detailsCorrect answerC
Single choice
A business unit within your organization intends to deploy a new technology in a manner that places it in violation of existing information security standards. What immediate action should the information security manager take? Reveal answer details Close answer detailsCorrect answerC
Single choice
The Information Security Management program MUST protect: Reveal answer details Close answer detailsCorrect answerB
Single choice
Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined security policy and framework for their Information Security Program. Your new boss, the Chief Financial Officer, has asked you to draft an outline of a security policy and recommend an industry/sector neutral information security control framework for implementation. Which of the following industry / sector neutral information security control frameworks should you recommend for implementation? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following strategies provides the BEST response to a ransomware attack? Reveal answer details Close answer detailsCorrect answerB
Single choice
A newly appointed security officer finds data leakage software licenses that had never been used. The officer decides to implement a project to ensure it gets installed, but the project gets a great deal of resistance across the organization. Which of the following represents the MOST likely reason for this situation? Reveal answer details Close answer detailsCorrect answerB
Single choice
A missing/ineffective security control is identified. Which of the following should be the NEXT step? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which International Organization for Standardization (ISO) below BEST describes the performance of risk management, and includes a five-stage risk management methodology. Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following represents the best method of ensuring business unit alignment with security program requirements? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following is MOST important when tuning an Intrusion Detection System (IDS)? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following tests is an IS auditor performing when a sample of programs is selected to determine if the source and object versions are the same? Reveal answer details Close answer detailsCorrect answerB
Single choice
An application vulnerability assessment has identified a security flaw in an application. This is a flaw that was previously identified and remediated on a prior release of the application. Which of the following is MOST likely the reason for this recurring issue? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following functions evaluates patches used to close software vulnerabilities of new systems to assure compliance with policy when implementing an information security program? Reveal answer details Close answer detailsCorrect answerA
Single choice
A global health insurance company is concerned about protecting confidential information. Which of the following is of MOST concern to this organization? Reveal answer details Close answer detailsCorrect answerD
Single choice
The regular review of a firewall ruleset is considered a Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following is a fundamental component of an audit record? Reveal answer details Close answer detailsCorrect answerA
Single choice
Smith, the project manager for a larger multi-location firm, is leading a software project team that has 18 members, 5 of which are assigned to testing. Due to recent recommendations by an organizational quality audit team, the project manager is convinced to add a quality professional to lead to test team at additional cost to the project. The project manager is aware of the importance of communication for the success of the project and takes the step of introducing additional communication channels, making it more complex, in order to assure quality levels of the project. What will be the first project management document that Smith should change in order to accommodate additional communication channels? Reveal answer details Close answer detailsCorrect answerA
Single choice
When creating contractual agreements and procurement processes why should security requirements be included? Reveal answer details Close answer detailsCorrect answerB
Single choice
A CISO wants to change the defense strategy to ward off attackers. To accomplish this the CISO is looking to a strategy where attackers are lured into a zone of a safe network where attackers can be monitored, controlled, quarantined, or eradicated. Reveal answer details Close answer detailsCorrect answerD
Single choice
When managing the security architecture for your company you must consider: Reveal answer details Close answer detailsCorrect answerD
Single choice
When project costs continually increase throughout implementation due to large or rapid changes in customer or user requirements, this is commonly known as: Reveal answer details Close answer detailsCorrect answerB Explanation References:
Single choice
You currently cannot provide for 24/7 coverage of your security monitoring and incident response duties and your company is resistant to the idea of adding more full-time employees to the payroll. Which combination of solutions would help to provide the coverage needed without the addition of more dedicated staff? (choose the best answer): Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following is MOST important when dealing with an Information Security Steering committee: Reveal answer details Close answer detailsCorrect answerC
Single choice
A recent audit has identified a few control exceptions and is recommending the implementation of technology and processes to address the finding. Which of the following is the MOST likely reason for the organization to reject the implementation of the recommended technology and processes? Reveal answer details Close answer detailsCorrect answerC
Single choice
Risk appetite directly affects what part of a vulnerability management program? Reveal answer details Close answer detailsCorrect answerB
Single choice
According to the National Institute of Standards and Technology (NIST) SP 800-40, which of the following considerations are MOST important when creating a vulnerability management program? Reveal answer details Close answer detailsCorrect answerA
Single choice
Your incident response plan should include which of the following? Reveal answer details Close answer detailsCorrect answerC
Single choice
What is the SECOND step to creating a risk management methodology according to the National Institute of Standards and Technology (NIST) SP 800-30 standard? Reveal answer details Close answer detailsCorrect answerD
Single choice
You have purchased a new insurance policy as part of your risk strategy. Which of the following risk strategy options have you engaged in? Reveal answer details Close answer detailsCorrect answerC
Single choice
When dealing with a risk management process, asset classification is important because it will impact the overall: Reveal answer details Close answer detailsCorrect answerC
Single choice
Information security policies should be reviewed: Reveal answer details Close answer detailsCorrect answerA
Single choice
What is the primary reason for performing vendor management? Reveal answer details Close answer detailsCorrect answerA
Single choice
To get an Information Security project back on schedule, which of the following will provide the MOST help? Reveal answer details Close answer detailsCorrect answerA
Single choice
Your company has a "no right to privacy" notice on all logon screens for your information systems and users sign an Acceptable Use Policy informing them of this condition. A peer group member and friend comes to you and requests access to one of her employee's email account. What should you do? (choose the BEST answer): Reveal answer details Close answer detailsCorrect answerB
Single choice
Providing oversight of a comprehensive information security program for the entire organization is the primary responsibility of which group under the InfoSec governance framework? Reveal answer details Close answer detailsCorrect answerA
Single choice
In order for a CISO to have true situational awareness there is a need to deploy technology that can give a real-time view of security events across the enterprise. Which tool selection represents the BEST choice to achieve situational awareness? Reveal answer details Close answer detailsCorrect answerD |