A missing/ineffective security control is identified.
Which of the following should be the NEXT step?
Show answer and explanation
Correct answer: C
712-50 Real Exam Questions
468 questions available · Page 1 of 47
Updated Exam DumpsVerified AnswersPass Guarantee
A missing/ineffective security control is identified.
Which of the following should be the NEXT step?
Correct answer: C
Which of the following is critical in creating a security program aligned with an organization's goals?
Correct answer: A
Risk is defined as:
Correct answer: B
risk = likelihood x impact (or damage incurred by the event. If you put a dollar value on the impact, then you can value the risk and in a simple way compare one risk factor to another)
Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate controls. You assign work to your staff to create or adjust existing security controls to ensure they are adequate for risk mitigation needs.
When adjusting the controls to mitigate the risks, how often should the CISO perform an audit to verify the controls?
Correct answer: C
Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined security policy and framework for their Information Security Program. Your new boss, the Chief Financial Officer, has asked you to draft an outline of a security policy and recommend an industry/sector neutral information security control framework for implementation.
Which of the following industry / sector neutral information security control frameworks should you recommend for implementation?
Correct answer: C
To have accurate and effective information security policies how often should the CISO review the organization policies?
Correct answer: B
Step-by-step procedures to regain normalcy in the event of a major earthquake is PRIMARILY covered by which of the following plans?
Correct answer: C
To make sure that the actions of all employees, applications, and systems follow the organization's rules and regulations can BEST be described as which of the following?
Correct answer: A
Which of the following statements about Encapsulating Security Payload (ESP) is true?
Correct answer: A
Which of the following is the MAIN reason to follow a formal risk management process in an organization that hosts and uses privately identifiable information (PII) as part of their business models and processes?
Correct answer: D