Skip to main content

712-50 Real Exam Questions

EC-Council Certified CISO (CCISO)

468 questions available · Page 1 of 47

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

A missing/ineffective security control is identified.

Which of the following should be the NEXT step?

  1. A

    Perform an audit to measure the control formally

  2. B

    Escalate the issue to the IT organization

  3. C

    Perform a risk assessment to measure risk

  4. D

    Establish Key Risk Indicators

Show answer and explanation

Correct answer: C

Question 2 Single choice

Which of the following is critical in creating a security program aligned with an organization's goals?

  1. A

    Develop a culture in which users, managers and IT professionals all make good decisions about information risk

  2. B

    Provide clear communication of security program support requirements and audit schedules

  3. C

    Create security awareness programs that include clear definition of security program goals and charters

  4. D

    Ensure security budgets enable technical acquisition and resource allocation based in internal compliance requirements

Show answer and explanation

Correct answer: A

Question 3 Single choice

Risk is defined as:

  1. A

    Quantitative plus qualitative impact

  2. B

    Asset loss times likelihood of event

  3. C

    Advisory plus capability plus vulnerability

  4. D

    Threat times vulnerability divided by control

Show answer and explanation

Correct answer: B

Explanation

risk = likelihood x impact (or damage incurred by the event. If you put a dollar value on the impact, then you can value the risk and in a simple way compare one risk factor to another)

Question 4 Single choice

Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate controls. You assign work to your staff to create or adjust existing security controls to ensure they are adequate for risk mitigation needs.

When adjusting the controls to mitigate the risks, how often should the CISO perform an audit to verify the controls?

  1. A

    Never

  2. B

    Quarterly

  3. C

    Annually

  4. D

    Semi-annually

Show answer and explanation

Correct answer: C

Question 5 Single choice

Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined security policy and framework for their Information Security Program. Your new boss, the Chief Financial Officer, has asked you to draft an outline of a security policy and recommend an industry/sector neutral information security control framework for implementation.

Which of the following industry / sector neutral information security control frameworks should you recommend for implementation?

  1. A

    Payment Card Industry Digital Security Standard (PCI DSS)

  2. B

    National Institute of Standards and Technology (NIST) Special Publication 800-53

  3. C

    International Organization for Standardization ?ISO 27001/2

  4. D

    British Standard 7799 (BS7799)

Show answer and explanation

Correct answer: C

Question 6 Single choice

To have accurate and effective information security policies how often should the CISO review the organization policies?

  1. A

    Before an audit

  2. B

    At least once a year

  3. C

    Quarterly

  4. D

    Every 6 months

Show answer and explanation

Correct answer: B

Question 7 Single choice

Step-by-step procedures to regain normalcy in the event of a major earthquake is PRIMARILY covered by which of the following plans?

  1. A

    Damage control plan

  2. B

    Disaster recovery plan

  3. C

    Business Continuity plan

  4. D

    Incident response plan

Show answer and explanation

Correct answer: C

Question 8 Single choice

To make sure that the actions of all employees, applications, and systems follow the organization's rules and regulations can BEST be described as which of the following?

  1. A

    Compliance management

  2. B

    Asset management

  3. C

    Risk management

  4. D

    Security management

Show answer and explanation

Correct answer: A

Question 9 Single choice

Which of the following statements about Encapsulating Security Payload (ESP) is true?

  1. A

    It is an IPSec protocol

  2. B

    it is a text-based communication protocol

  3. C

    It uses UDP port 22

  4. D

    It uses TCP port 22 as the default port and operates at the application layer

Show answer and explanation

Correct answer: A

Question 10 Single choice

Which of the following is the MAIN reason to follow a formal risk management process in an organization that hosts and uses privately identifiable information (PII) as part of their business models and processes?

  1. A

    Need to comply with breach disclosure laws

  2. B

    Fiduciary responsibility to safeguard credit information

  3. C

    Need to transfer the risk associated with hosting PII data

  4. D

    Need to better understand the risk associated with using PII data

Show answer and explanation

Correct answer: D