[Jan 24, 2022] Pass 712-50 Review Guide, Reliable 712-50 Test Engine [Q110-Q132]

Share

[Jan 24, 2022] Pass 712-50 Review Guide, Reliable 712-50 Test Engine

712-50 Test Engine Practice Test Questions, Exam Dumps

NEW QUESTION 110
An international organization is planning a project to implement encryption technologies to protect company confidential information. This organization has data centers on three continents. Which of the following would be considered a MAJOR constraint for the project?

  • A. Time zone differences
  • B. Local customer privacy laws
  • C. Compliance to local hiring laws
  • D. Encryption import/export regulations

Answer: D

 

NEW QUESTION 111
The regular review of a firewall ruleset is considered a _______________________.

  • A. Management control
  • B. Organization control
  • C. Procedural control
  • D. Technical control

Answer: C

 

NEW QUESTION 112
Which is the BEST solution to monitor, measure, and report changes to critical data in a system?

  • A. SNMP traps
  • B. Syslog
  • C. Application logs
  • D. File integrity monitoring

Answer: D

Explanation:
Explanation

 

NEW QUESTION 113
Creating a secondary authentication process for network access would be an example of?

  • A. Anti-virus for mobile devices
  • B. Nonlinearities in physical security performance metrics
  • C. System hardening and patching requirements
  • D. Defense in depth cost enumerated costs

Answer: B

 

NEW QUESTION 114
Which of the following is the MAIN reason to follow a formal risk management process in an organization that hosts and uses privately identifiable information (PII) as part of their business models and processes?

  • A. Need to transfer the risk associated with hosting PII data
  • B. Fiduciary responsibility to safeguard credit card information
  • C. Need to better understand the risk associated with using PII data
  • D. Need to comply with breach disclosure laws

Answer: C

 

NEW QUESTION 115
Which of the following statements about Encapsulating Security Payload (ESP) is true?

  • A. It uses UDP port 22
  • B. it is a text-based communication protocol
  • C. It is an IPSec protocol
  • D. It uses TCP port 22 as the default port and operates at the application layer

Answer: C

Explanation:
Explanation/Reference:

 

NEW QUESTION 116
In terms of supporting a forensic investigation, it is now imperative that managers, firstresponders, etc., accomplish the following actions to the computer under investigation:

  • A. Secure the area and shut down the computer until investigators arrive
  • B. Secure the area and attempt to maintain power until investigators arrive
  • C. Secure the area
  • D. Immediately place hard drive and other components in an anti-static bag

Answer: B

 

NEW QUESTION 117
You currently cannot provide for 24/7 coverage of your security monitoring and incident response duties and your company is resistant to the idea of adding more full-time employees to the payroll.
Which combination of solutions would help to provide the coverage needed without the addition of more dedicated staff?

  • A. Employ an assumption of breach protocol and defend only essential information resources.
  • B. Contract with a managed security provider and have current staff on recall for incident response
  • C. Configure your syslog to send SMS messages to current staff when target events are triggered.
  • D. Deploy a SEIM solution and have current staff review incidents first in the morning

Answer: B

Explanation:
Explanation

 

NEW QUESTION 118
SCENARIO: A CISO has several two-factor authentication systems under review and selects the one that is most sufficient and least costly. The implementation project planning is completed and the teams are ready to implement the solution. The CISO then discovers that the product it is not as scalable as originally thought and will not fit the organization's needs.
The CISO is unsure of the information provided and orders a vendor proof of concept to validate the system's scalability. This demonstrates which of the following?

  • A. A methodology-based approach to ensure authentication mechanism functions
  • B. An approach providing minimum time impact to the implementation schedules
  • C. A risk-based approach to determine if the solution is suitable for investment
  • D. An approach that allows for minimum budget impact if the solution is unsuitable

Answer: C

 

NEW QUESTION 119
An organization's firewall technology needs replaced. A specific technology has been selected that is less costly than others and lacking in some important capabilities. The security officer has voiced concerns about sensitive data breaches but the decision is made to purchase.
What does this selection indicate?

  • A. A high risk tolerance environment
  • B. A low risk tolerance environment
  • C. I low vulnerability environment
  • D. A high threat environment

Answer: A

 

NEW QUESTION 120
You work as a project manager for TYU project. You are planning for risk mitigation. You need to quickly identify high-level risks that will need a more in-depth analysis.
Which of the following activities will help you in this?

  • A. Qualitative analysis
  • B. Estimate activity duration
  • C. Risk mitigation
  • D. Quantitative analysis

Answer: A

 

NEW QUESTION 121
Which of the following is critical in creating a security program aligned with an organization's goals?

  • A. Provide clear communication of security program support requirements and audit schedules
  • B. Ensure security budgets enable technical acquisition and resource allocation based on internal compliance requirements
  • C. Develop a culture in which users, managers and IT professionals all make good decisions about information risk
  • D. Create security awareness programs that include clear definition of security program goals and charters

Answer: C

 

NEW QUESTION 122
What type of attack requires the least amount of technical equipment and has the highest success rate?

  • A. Social engineering
  • B. War driving
  • C. Operating system attacks
  • D. Shrink wrap attack

Answer: A

 

NEW QUESTION 123
What is the main purpose of the Incident Response Team?

  • A. Communicate details of information security incidents
  • B. Provide current employee awareness programs
  • C. Create effective policies detailing program activities
  • D. Ensure efficient recovery and reinstate repaired systems

Answer: D

 

NEW QUESTION 124
Which of the following is a major benefit of applying risk levels?

  • A. Risk budgets are more easily managed due to fewer due to fewer identified risks as a result of using a methodology
  • B. Resources are not wasted on risks that are already managed to an acceptable level
  • C. Risk management governance becomes easier since most risks remain low once mitigated
  • D. Risk appetite increase within the organization once the levels are understood

Answer: B

Explanation:
Explanation/Reference:

 

NEW QUESTION 125
In which of the following cases, would an organization be more prone to risk acceptance vs. risk mitigation?

  • A. The organization uses exclusively a quantitative process to measure risk
  • B. The organization's risk tolerance is lo
  • C. The organization uses exclusively a qualitative process to measure risk
  • D. The organization's risk tolerance is high

Answer: D

 

NEW QUESTION 126
The Information Security Management program MUST protect:

  • A. critical business processes and /or revenue streams
  • B. all organizational assets
  • C. intellectual property released into the public domain
  • D. against distributed denial of service attacks

Answer: A

 

NEW QUESTION 127
You have recently drafted a revised information security policy. From whom should you seek endorsement in order to have the GREATEST chance for adoption and implementation throughout the entire organization?

  • A. Chief Information Security Officer
  • B. Chief Information Officer
  • C. Chief Legal Counsel
  • D. Chief Executive Officer

Answer: D

Explanation:
ECCouncil 712-50 : Practice Test

 

NEW QUESTION 128
Which of the following illustrates an operational control process:

  • A. Classifying an information system as part of a risk assessment
  • B. Conducting an audit of the configuration management process
  • C. Installing an appropriate fire suppression system in the data center
  • D. Establishing procurement standards for cloud vendors

Answer: C

 

NEW QUESTION 129
Which of the following tests is an IS auditor performing when a sample of programs is selected to determine if the source and object versions are the same?

  • A. A compliance test of program library controls
  • B. A substantive test of the program compiler controls
  • C. A compliance test of the program compiler controls
  • D. A substantive test of program library controls

Answer: A

 

NEW QUESTION 130
Creating good security metrics is essential for a CISO. What would be the BEST sources for creating security metrics for baseline defenses coverage?

  • A. Firewall, exchange, web server, intrusion detection system (IDS)
  • B. IDS, syslog, router, switches
  • C. Firewall, anti-virus console, IDS, syslog
  • D. Servers, routers, switches, modem

Answer: C

 

NEW QUESTION 131
Scenario: Your organization employs single sign-on (user name and password only) as a convenience to your employees to access organizational systems and data. Permission to individual systems and databases is vetted and approved through supervisors and data owners to ensure that only approved personnel can use particular applications or retrieve information. All employees have access to their own human resource information, including the ability to change their bank routing and account information and other personal details through the Employee Self-Service application. All employees have access to the organizational VPN.
Recently, members of your organization have been targeted through a number of sophisticated phishing attempts and have compromised their system credentials. What action can you take to prevent the misuse of compromised credentials to change bank account information from outside your organization while still allowing employees to manage their bank information?

  • A. Enable monitoring on the VPN for suspicious activity
  • B. Force a change of all passwords
  • C. Turn off VPN access for users originating from outside the country
  • D. Block access to the Employee-Self Service application via VPN

Answer: D

 

NEW QUESTION 132
......

100% Free 712-50 Daily Practice Exam With 447 Questions: https://exams4sure.pass4sures.top/EC-CCISO/712-50-testking-braindumps.html