
512-50 Braindumps PDF, EC-COUNCIL 512-50 Exam Cram
New 2022 512-50 Sample Questions Reliable 512-50 Test Engine
NEW QUESTION 155
The regular review of a firewall ruleset is considered a
- A. Organization control
- B. Procedural control
- C. Technical control
- D. Management control
Answer: B
NEW QUESTION 156
Scenario: Most industries require compliance with multiple government regulations and/or industry standards to meet data protection and privacy mandates.
When multiple regulations or standards apply to your industry you should set controls to meet the:
- A. Most complex standard to implement
- B. Stricter regulation or standard
- C. Easiest regulation or standard to implement
- D. Recommendations of your Legal Staff
Answer: C
NEW QUESTION 157
The success of the Chief Information Security Officer is MOST dependent upon:
- A. raising awareness of security issues with end users
- B. following the recommendations of consultants and contractors
- C. development of relationships with organization executives
- D. favorable audit findings
Answer: C
NEW QUESTION 158
The mean time to patch, number of virus outbreaks prevented, and number of vulnerabilities mitigated are examples of what type of performance metrics?
- A. Operational metrics
- B. Compliance metrics
- C. Management metrics
- D. Risk metrics
Answer: A
NEW QUESTION 159
SCENARIO: Critical servers show signs of erratic behavior within your organization's intranet. Initial information indicates the systems are under attack from an outside entity. As the Chief Information Security Officer (CISO), you decide to deploy the Incident Response Team (IRT) to determine the details of this incident and take action according to the information available to the team.
What phase of the response provides measures to reduce the likelihood of an incident from recurring?
- A. Investigation
- B. Follow-up
- C. Response
- D. Recovery
Answer: B
NEW QUESTION 160
Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small retail merchant but it is expected to grow to a global customer base of many millions of customers in just a few years.
Which of the following would be the FIRST step when addressing Information Security formally and consistently in this organization?
- A. Create an executive security steering committee
- B. Define formal roles and responsibilities for Information Security
- C. Define formal roles and responsibilities for Internal audit functions
- D. Contract a third party to perform a security risk assessment
Answer: B
NEW QUESTION 161
The network administrator wants to strengthen physical security in the organization. Specifically, to implement a solution stopping people from entering certain restricted zones without proper credentials. Which of following physical security measures should the administrator use?
- A. Fence
- B. Bollards
- C. Mantrap
- D. Video surveillance
Answer: A
NEW QUESTION 162
The patching and monitoring of systems on a consistent schedule is required by?
- A. Audit best practices
- B. Local privacy laws
- C. Industry best practices
- D. Risk Management frameworks
Answer: D
NEW QUESTION 163
What oversight should the information security team have in the change management process for application security?
- A. Information security should be informed of changes to applications only
- B. Development team should tell the information security team about any application security flaws
- C. Information security should be aware of any significant application security changes and work with developer to test for vulnerabilities before changes are deployed in production
- D. Information security should be aware of all application changes and work with developers before changes are deployed in production
Answer: C
NEW QUESTION 164
At what level of governance are individual projects monitored and managed?
- A. Enterprise
- B. Portfolio
- C. Milestone
- D. Program
Answer: B
NEW QUESTION 165
Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate controls. You assign work to your staff to create or adjust existing security controls to ensure they are adequate for risk mitigation needs.
When formulating the remediation plan, what is a required input?
- A. Board of directors
- B. Latest virus definitions file
- C. Patching history
- D. Risk assessment
Answer: D
NEW QUESTION 166
An organization's firewall technology needs replaced. A specific technology has been selected that is less costly than others and lacking in some important capabilities. The security officer has voiced concerns about sensitive data breaches but the decision is made to purchase. What does this selection indicate?
- A. A high threat environment
- B. A high risk tolerance environment
- C. I low vulnerability environment
- D. A low risk tolerance environment
Answer: B
NEW QUESTION 167
You are the Chief Information Security Officer of a large, multinational bank and you suspect there is a flaw in a two factor authentication token management process. Which of the following represents your BEST course of action?
- A. Send a report to executive peers and business unit owners detailing your suspicions
- B. Conduct a thorough risk assessment against the current implementation to determine system functions
- C. Determine program ownership to implement compensating controls
- D. Validate that security awareness program content includes information about the potential vulnerability
Answer: B
NEW QUESTION 168
SQL injection is a very popular and successful injection attack method. Identify the basic SQL injection text:
- A. NOPS
- B. "DROPTABLE USERNAME"
- C. /../../../../
- D. ' o 1=1 - -
Answer: D
NEW QUESTION 169
Which of the following is of MOST importance when security leaders of an organization are required to align security to influence the culture of an organization?
- A. Understand the business goals of the organization
- B. Understand all regulations affecting the organization
- C. Poses a strong technical background
- D. Poses a strong auditing background
Answer: A
NEW QUESTION 170
Which of the following illustrates an operational control process:
- A. Installing an appropriate fire suppression system in the data center
- B. Conducting an audit of the configuration management process
- C. Classifying an information system as part of a risk assessment
- D. Establishing procurement standards for cloud vendors
Answer: A
NEW QUESTION 171
From an information security perspective, information that no longer supports the main purpose of the business should be:
- A. analyzed under the retention policy
- B. protected under the information classification policy.
- C. assessed by a business impact analysis.
- D. analyzed under the data ownership policy.
Answer: A
NEW QUESTION 172
Scenario: Your organization employs single sign-on (user name and password only) as a convenience to your employees to access organizational systems and data. Permission to individual systems and databases is vetted and approved through supervisors and data owners to ensure that only approved personnel can use particular applications or retrieve information. All employees have access to their own human resource information, including the ability to change their bank routing and account information and other personal details through the Employee Self-Service application. All employees have access to the organizational VPN.
Once supervisors and data owners have approved requests, information system administrators will implement
- A. Operational control(s)
- B. Management control(s)
- C. Technical control(s)
- D. Policy control(s)
Answer: C
NEW QUESTION 173
Knowing the potential financial loss an organization is willing to suffer if a system fails is a determination of which of the following?
- A. Business continuity
- B. Likelihood of impact
- C. Cost benefit
- D. Risk appetite
Answer: D
NEW QUESTION 174
As the Chief Information Security Officer, you are performing an assessment of security posture to understand what your Defense-in-Depth capabilities are. Which network security technology examines network traffic flows to detect and actively stop vulnerability exploits and attacks?
- A. Gigamon
- B. Anti-virus
- C. Intrusion Prevention System
- D. Port Security
Answer: C
Explanation:
Reference: https://searchsecurity.techtarget.com/definition/intrusion-prevention
NEW QUESTION 175
After a risk assessment is performed, a particular risk is considered to have the potential of costing the organization 1.2 Million USD. This is an example of
- A. Risk Appetite
- B. Qualitative risk analysis
- C. Risk Tolerance
- D. Quantitative risk analysis
Answer: D
NEW QUESTION 176
When deploying an Intrusion Prevention System (IPS) the BEST way to get maximum protection from the system is to deploy it
- A. In promiscuous mode and block malicious traffic.
- B. In promiscuous mode and only detect malicious traffic.
- C. In-line and turn on blocking mode to stop malicious traffic.
- D. In-line and turn on alert mode to stop malicious traffic.
Answer: C
NEW QUESTION 177
You have a system with 2 identified risks. You determine the probability of one risk occurring is higher than the
- A. Relative likelihood of event
- B. Risk impact comparison
- C. Controlled mitigation effort
- D. Comparative threat analysis
Answer: A
NEW QUESTION 178
......
Feel EC-COUNCIL 512-50 Dumps PDF Will likely be The best Option: https://www.free4torrent.com/512-50-braindumps-torrent.html
512-50 exam torrent EC-COUNCIL study guide: https://drive.google.com/open?id=1JP_juvVUekmz2ceKt0Yh-bpeg6kmslDW