512-50 Exam Details

  • Exam Code
    :512-50
  • Exam Name
    :EC-Council Information Security Manager (E|ISM)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :404 Q&As
  • Last Updated
    :May 25, 2026

EC-COUNCIL 512-50 Online Questions & Answers

  • Question 131:

    Network Forensics is the prerequisite for any successful legal action after attacks on your Enterprise Network. Which is the single most important factor to introducing digital evidence into a court of law?

    A. Comprehensive Log-Files from all servers and network devices affected during the attack
    B. Fully trained network forensic experts to analyze all data right after the attack
    C. Uninterrupted Chain of Custody
    D. Expert forensics witness

  • Question 132:

    A security manager has created a risk program. Which of the following is a critical part of ensuring the program is successful?

    A. Providing a risk program governance structure
    B. Ensuring developers include risk control comments in code
    C. Creating risk assessment templates based on specific threats
    D. Allowing for the acceptance of risk for regulatory compliance requirements

  • Question 133:

    A Chief Information Security Officer received a list of high, medium, and low impact audit findings. Which of the following represents the BEST course of action?

    A. If the findings impact regulatory compliance, try to apply remediation that will address the most findings for the least cost.
    B. If the findings do not impact regulatory compliance, remediate only the high and medium risk findings.
    C. If the findings impact regulatory compliance, remediate the high findings as quickly as possible.
    D. If the findings do not impact regulatory compliance, review current security controls.

  • Question 134:

    Scenario: Your corporate systems have been under constant probing and attack from foreign IP addresses for more than a week. Your security team and security infrastructure have performed well under the stress. You are confident that your defenses have held up under the test, but rumors are spreading that sensitive customer data has been stolen and is now being sold on the Internet by criminal elements. During your investigation of the rumored compromise you discover that data has been breached and you have discovered the repository of stolen data on a server located in a foreign country. Your team now has full access to the data on the foreign server.

    Your defenses did not hold up to the test as originally thought. As you investigate how the data was compromised through log analysis you discover that a hardworking, but misguided business intelligence analyst posted the data to an obfuscated URL on a popular cloud storage service so they could work on it from home during their off-time.

    Which technology or solution could you deploy to prevent employees from removing corporate data from your network? Choose the BEST answer.

    A. Security Guards posted outside the Data Center
    B. Data Loss Prevention (DLP)
    C. Rigorous syslog reviews
    D. Intrusion Detection Systems (IDS)

  • Question 135:

    The amount of risk an organization is willing to accept in pursuit of its mission is known as

    A. Risk mitigation
    B. Risk transfer
    C. Risk tolerance
    D. Risk acceptance

  • Question 136:

    Information Security is often considered an excessive, after-the-fact cost when a project or initiative is completed. What can be done to ensure that security is addressed cost effectively?

    A. User awareness training for all employees
    B. Installation of new firewalls and intrusion detection systems
    C. Launch an internal awareness campaign
    D. Integrate security requirements into project inception

  • Question 137:

    A CISO has recently joined an organization with a poorly implemented security program. The desire is to base the security program on a risk management approach. Which of the following is a foundational requirement in order to initiate this type of program?

    A. A security organization that is adequately staffed to apply required mitigation strategies and regulatory compliance solutions
    B. A clear set of security policies and procedures that are more concept-based than controls-based
    C. A complete inventory of Information Technology assets including infrastructure, networks, applications and data
    D. A clearly identified executive sponsor who will champion the effort to ensure organizational buy-in

  • Question 138:

    Which of the following are primary concerns for management with regard to assessing internal control objectives?

    A. Confidentiality, Availability, Integrity
    B. Compliance, Effectiveness, Efficiency
    C. Communication, Reliability, Cost
    D. Confidentiality, Compliance, Cost

  • Question 139:

    As a CISO you need to understand the steps that are used to perform an attack against a network. Put each step into the correct order.

    1.Covering tracks 2.Scanning and enumeration 3.Maintaining Access 4.Reconnaissance 5.Gaining Access

    A. 4, 2, 5, 3, 1
    B. 2, 5, 3, 1, 4
    C. 4, 5, 2, 3, 1
    D. 4, 3, 5, 2, 1

  • Question 140:

    You have implemented a new security control. Which of the following risk strategy options have you engaged in?

    A. Risk Avoidance
    B. Risk Acceptance
    C. Risk Transfer
    D. Risk Mitigation

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 512-50 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.