Sign In
Home/EC-Council/712-50: EC-Council Certified CISO/Free questions

712-50: EC-Council Certified CISO — Free Practice Questions

10 free sample questions from a bank of 484, with the correct answers and explanations. No signup required — start practising right now.

1When briefing senior management on the creation of a governance process, the MOST important aspect should be:
  • knowledge required to analyze each issue
  • information security metrics
  • linkage to business area objectives
  • baseline against which metrics are evaluated
Answer: C
2Which of the following should be determined while defining risk management strategies?
  • Organizational objectives and risk tolerance
  • Enterprise disaster recovery plans
  • Risk assessment criteria
  • IT architecture complexity
Answer: A
3Which of the following is the MOST important benefit of an effective security governance process?
  • Senior management participation in the incident response process
  • Better vendor management
  • Reduction of security breaches
  • Reduction of liability and overall risk to the organization
Answer: D
4A global retail organization is looking to implement a consistent Disaster Recovery and Business Continuity Process across all of its business units. Which of the following standards and guidelines can BEST address this organization's need?
  • International Organization for Standardizations ג€" 22301 (ISO-22301)
  • Information Technology Infrastructure Library (ITIL)
  • Payment Card Industry Data Security Standards (PCI-DSS)
  • International Organization for Standardizations ג€" 27005 (ISO-27005)
Answer: A
5A security manager regularly checks work areas after business hours for security violations; such as unsecured files or unattended computers with active sessions. This activity BEST demonstrates what part of a security program?
  • Compliance management
  • Audit validation
  • Physical control testing
  • Security awareness training
Answer: A
6Which of the following is the MAIN reason to follow a formal risk management process in an organization that hosts and uses privately identifiable information (PII) as part of their business models and processes?
  • Need to comply with breach disclosure laws
  • Fiduciary responsibility to safeguard credit information
  • Need to transfer the risk associated with hosting PII data
  • Need to better understand the risk associated with using PII data
Answer: D
7A method to transfer risk is to______________.
  • Implement redundancy
  • Move operations to another region
  • Align to business operations
  • Purchase breach insurance
Answer: D
8An organization licenses and uses personal information for business operations, and a server containing that information has been compromised. What kind of law would require notifying the owner or licensee of this incident?
  • Consumer right disclosure
  • Data breach disclosure
  • Special circumstance disclosure
  • Security incident disclosure
Answer: B
9Why is it vitally important that senior management endorse a security policy?
  • So that employees will follow the policy directives.
  • So that they can be held legally accountable.
  • So that external bodies will recognize the organizations commitment to security.
  • So that they will accept ownership for security within the organization.
Answer: D
10Which of the following is of MOST importance when security leaders of an organization are required to align security to influence the culture of an organization?
  • Understand the business goals of the organization
  • Poses a strong technical background
  • Poses a strong auditing background
  • Understand all regulations affecting the organization
Answer: A

Want the full bank of 484 questions for 712-50: EC-Council Certified CISO? See all practice exams.