
[Feb 03, 2022] Latest 712-50 Exam with Accurate EC-Council Certified CISO (CCISO) PDF Questions
Practice To 712-50 - Prep4King Remarkable Practice On your EC-Council Certified CISO (CCISO) Exam
NEW QUESTION 42
You are just hired as the new CISO and are being briefed on all the Information Security projects that your section has on going. You discover that most projects are behind schedule and over budget.
Using the best business practices for project management you determine that the project correct aligns with the company goals. What needs to be verified FIRST?
- A. Vendor for the project
- B. Scope of the project
- C. Timeline of the project milestones
- D. Training of the personnel on the project
Answer: B
NEW QUESTION 43
Your organization provides open guest wireless access with no captive portals. What can you do to assist with law enforcement investigations if one of your guests is suspected of committing an illegal act using your network?
- A. Disable SSID Broadcast and enable MAC address filtering on all wireless access points.
- B. Provide IP and MAC address
- C. Configure logging on each access point
- D. Install a firewall software on each wireless access point.
Answer: B
NEW QUESTION 44
The effectiveness of an audit is measured by?
- A. The number of actionable items in the recommendations
- B. How the recommendations directly support the goals of the company
- C. The number of security controls the company has in use
- D. How it exposes the risk tolerance of the company
Answer: B
NEW QUESTION 45
Which of the following best describes the purpose of the International Organization for Standardization (ISO) 27002 standard?
- A. To established guidelines and general principles for initiating, implementing, maintaining, and improving information security management within an organization
- B. To provide a common basis for developing organizational security standards
- C. To provide effective security management practice and to provide confidence in inter-organizational dealings
- D. To give information security management recommendations to those who are responsible for initiating, implementing, or maintaining security in their organization.
Answer: A
NEW QUESTION 46
You have implemented the new controls. What is the next step?
- A. Monitor the effectiveness of the controls
- B. Update the audit findings report
- C. Document the process for the stakeholders
- D. Perform a risk assessment
Answer: A
NEW QUESTION 47
Which of the following is a common technology for visual monitoring?
- A. Open circuit television
- B. Blocked video
- C. Local video
- D. Closed circuit television
Answer: D
Explanation:
Explanation/Reference: https://www.ifsecglobal.com/video-surveillance/role-cctv-cameras-public-privacy-protection/
NEW QUESTION 48
In terms of supporting a forensic investigation, it is now imperative that managers, first-responders, etc., accomplish the following actions to the computer under investigation:
- A. Secure the area.
- B. Immediately place hard drive and other components in an anti-static bag
- C. Secure the area and shut-down the computer until investigators arrive
- D. Secure the area and attempt to maintain power until investigators arrive
Answer: D
NEW QUESTION 49
When entering into a third party vendor agreement for security services, at what point in the process is it BEST to understand and validate the security posture and compliance level of the vendor?
- A. Once the vendor is on premise and before they perform security services
- B. Once the agreement has been signed and the security vendor states that they will need access to the network
- C. Prior to signing the agreement and before any security services are being performed
- D. At the time the security services are being performed and the vendor needs access to the network
Answer: C
NEW QUESTION 50
Creating a secondary authentication process for network access would be an example of?
- A. Supporting the concept of layered security
- B. Putting undue time commitment on the system administrator.
- C. An administrator with too much time on their hands.
- D. Network segmentation.
Answer: A
NEW QUESTION 51
Your penetration testing team installs an in-line hardware key logger onto one of your network machines. Which of the following is of major concern to the security organization?
- A. In-line hardware keyloggers don't comply to industry regulations
- B. In-line hardware keyloggers are relatively inexpensive
- C. In-line hardware keyloggers don't require physical access
- D. In-line hardware keyloggers are undetectable by software
Answer: D
NEW QUESTION 52
An organization has defined a set of standard security controls. This organization has also defined the circumstances and conditions in which they must be applied. What is the NEXT logical step in applying the controls in the organization?
- A. Analyze existing controls on systems
- B. Determine the risk tolerance
- C. Create an architecture gap analysis
- D. Perform an asset classification
Answer: D
NEW QUESTION 53
The MOST common method to get an unbiased measurement of the effectiveness of an Information Security Management System (ISMS) is to_________________________.
- A. assign the responsibility to the team responsible for the management of the controls
- B. create operational reports on the effectiveness of the controls.
- C. assign the responsibility to the information security team
- D. perform an independent audit of the security controls
Answer: D
Explanation:
Explanation
NEW QUESTION 54
The process to evaluate the technical and non-technical security controls of an IT system to validate that a given design and implementation meet a specific set of security requirements is called
- A. Security certification
- B. Security system analysis
- C. Alignment with business practices and goals.
- D. Security accreditation
Answer: A
NEW QUESTION 55
The PRIMARY objective for information security program development should be:
- A. Establishing strategic alignment with bunsiness continuity requirements
- B. Establishing incident response programs.
- C. Identifying and implementing the best security solutions.
- D. Reducing the impact of the risk to the business.
Answer: D
NEW QUESTION 56
When managing the critical path of an IT security project, which of the following is MOST important?
- A. Knowing the milestones and timelines of deliverables.
- B. Knowing the people on the data center team.
- C. Knowing who all the stakeholders are.
- D. Knowing the threats to the organization.
Answer: A
NEW QUESTION 57
A company wants to fill a Chief Information Security Officer position in the organization. They need to define and implement a more holistic security program. Which of the following qualifications and experience would be MOST desirable to find in a candidate?
- A. College degree, audit capabilities and complex project management
- B. Multiple references, strong background check and industry certifications
- C. Multiple certifications, strong technical capabilities and lengthy resume
- D. Industry certifications, technical knowledge and program management skills
Answer: D
NEW QUESTION 58
When briefing senior management on the creation of a governance process, the MOST important aspect should be:
- A. information security metrics
- B. linkage to business area objectives
- C. knowledge required to analyze each issue
- D. baseline against which metrics are evaluated
Answer: B
NEW QUESTION 59
What oversight should the information security team have in the change management process for application security?
- A. Information security should be aware of any significant application security changes and work with developer to test for vulnerabilities before changes are deployed in production
- B. Development team should tell the information security team about any application security flaws
- C. Information security should be aware of all application changes and work with developers before changes are deployed in production
- D. Information security should be informed of changes to applications only
Answer: A
NEW QUESTION 60
A newly-hired CISO needs to understand the organization's financial management standards for business units and operations. Which of the following would be the best source of this information?
- A. The internal accounting department
- B. The managers of the accounts payables and accounts receivables teams
- C. The Chief Financial Officer (CFO)
- D. The external financial audit service
Answer: B
NEW QUESTION 61
Which of the following is the MOST effective method for discovering common technical vulnerabilities within the IT environment?
- A. Checking vendor product releases
- B. Performing system scans
- C. Reviewing system administrator logs
- D. Auditing configuration templates
Answer: B
NEW QUESTION 62
You have implemented the new controls. What is the next step?
- A. Monitor the effectiveness of the controls
- B. Update the audit findings report
- C. Document the process for the stakeholders
- D. Perform a risk assessment
Answer: A
NEW QUESTION 63
A CISO decides to analyze the IT infrastructure to ensure security solutions adhere to the concepts of how hardware and software is implemented and managed within the organization. Which of the following principles does this best demonstrate?
- A. Alignment with the business
- B. Leveraging existing implementations
- C. Proper budget management
- D. Effective use of existing technologies
Answer: A
NEW QUESTION 64
Scenario: Your company has many encrypted telecommunications links for their world-wide operations.
Physically distributing symmetric keys to all locations has proven to be administratively burdensome, but symmetric keys are preferred to other alternatives.
Symmetric encryption in general is preferable to asymmetric encryption when:
- A. The number of unique communication links is large
- B. The volume of data being transmitted is small
- C. The speed of the encryption / deciphering process is essential
- D. The distance to the end node is farthest away
Answer: C
NEW QUESTION 65
......
Exam Questions and Answers for 712-50 Study Guide Questions and Answers!: https://www.prep4king.com/712-50-exam-prep-material.html
Practice To 712-50 - Prep4King Remarkable Practice On your EC-Council Certified CISO (CCISO) Exam: https://drive.google.com/open?id=1spjLjPFqJFWDPWeu7nzhg-M8qeUGvFah

