Skip to main content

512-50 Real Exam Questions

EC-Council Information Security Manager (E|ISM)

404 questions available · Page 1 of 41

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Scenario: Your corporate systems have been under constant probing and attack from foreign IP addresses for more than a week. Your security team and security infrastructure have performed well under the stress.
You are confident that your defenses have held up under the test, but rumors are spreading that sensitive customer data has been stolen and is now being sold on the Internet by criminal elements. During your investigation of the rumored compromise you discover that data has been breached and you have discovered the repository of stolen data on a server located in a foreign country. Your team now has full

access to the data on the foreign server.

What action should you take FIRST?

  1. A

    Destroy the repository of stolen data

  2. B

    Contact your local law enforcement agency

  3. C

    Consult with other C-Level executives to develop an action plan

  4. D

    Contract with a credit reporting company for paid monitoring services for affected customers

Show answer and explanation

Correct answer: C

Question 2 Single choice

When is an application security development project complete?

  1. A

    When the application is retired.

  2. B

    When the application turned over to production.

  3. C

    When the application reaches the maintenance phase.

  4. D

    After one year.

Show answer and explanation

Correct answer: A

Question 3 Single choice

The establishment of a formal risk management framework and system authorization program is essential.
The LAST step of the system authorization process is:

  1. A

    Contacting the Internet Service Provider for an IP scope

  2. B

    Getting authority to operate the system from executive management

  3. C

    Changing the default passwords

  4. D

    Conducting a final scan of the live system and mitigating all high and medium level vulnerabilities

Show answer and explanation

Correct answer: B

Question 4 Single choice

A recommended method to document the respective roles of groups and individuals for a given process is to:

  1. A

    Develop a detailed internal organization chart

  2. B

    Develop a telephone call tree for emergency response

  3. C

    Develop an isolinear response matrix with cost benefit analysis projections

  4. D

    Develop a Responsible, Accountable, Consulted, Informed (RACI) chart

Show answer and explanation

Correct answer: D

Question 5 Single choice

You have a system with 2 identified risks. You determine the probability of one risk occurring is higher than the

  1. A

    Controlled mitigation effort

  2. B

    Risk impact comparison

  3. C

    Relative likelihood of event

  4. D

    Comparative threat analysis

Show answer and explanation

Correct answer: C

Question 6 Single choice

According to ISO 27001, of the steps for establishing an Information Security Governance program listed below, which comes first?

  1. A

    Identify threats, risks, impacts and vulnerabilities

  2. B

    Decide how to manage risk

  3. C

    Define the budget of the Information Security Management System

  4. D

    Define Information Security Policy

Show answer and explanation

Correct answer: D

Question 7 Single choice

Which of the following are not stakeholders of IT security projects?

  1. A

    Board of directors

  2. B

    Third party vendors

  3. C

    CISO

  4. D

    Help Desk

Show answer and explanation

Correct answer: B

Question 8 Single choice

Which of the following are primary concerns for management with regard to assessing internal control objectives?

  1. A

    Confidentiality, Availability, Integrity

  2. B

    Compliance, Effectiveness, Efficiency

  3. C

    Communication, Reliability, Cost

  4. D

    Confidentiality, Compliance, Cost

Show answer and explanation

Correct answer: B

Question 9 Single choice

You are just hired as the new CISO and are being briefed on all the Information Security projects that your section has on going. You discover that most projects are behind schedule and over budget.

Using the best business practices for project management you determine that the project correctly aligns with the company goals and the scope of the project is correct.

What is the NEXT step?

  1. A

    Review time schedules

  2. B

    Verify budget

  3. C

    Verify resources

  4. D

    Verify constraints

Show answer and explanation

Correct answer: C

Question 10 Single choice

A CISO sees abnormally high volumes of exceptions to security requirements and constant pressure from business units to change security processes.

Which of the following represents the MOST LIKELY cause of this situation?

  1. A

    Poor audit support for the security program

  2. B

    A lack of executive presence within the security program

  3. C

    Poor alignment of the security program to business needs

  4. D

    This is normal since business units typically resist security requirements

Show answer and explanation

Correct answer: C