712-50: EC-Council Certified CISO — Free Practice Questions
10 free sample questions from a bank of 484, with the correct answers and explanations. No signup required — start practising right now.
1When briefing senior management on the creation of a governance process, the MOST important aspect should be:
knowledge required to analyze each issue
information security metrics
linkage to business area objectives
baseline against which metrics are evaluated
Answer: C
2Which of the following should be determined while defining risk management strategies?
Organizational objectives and risk tolerance
Enterprise disaster recovery plans
Risk assessment criteria
IT architecture complexity
Answer: A
3Which of the following is the MOST important benefit of an effective security governance process?
Senior management participation in the incident response process
Better vendor management
Reduction of security breaches
Reduction of liability and overall risk to the organization
Answer: D
4A global retail organization is looking to implement a consistent Disaster Recovery and Business Continuity Process across all of its business units.
Which of the following standards and guidelines can BEST address this organization's need?
International Organization for Standardizations ג€" 22301 (ISO-22301)
Information Technology Infrastructure Library (ITIL)
Payment Card Industry Data Security Standards (PCI-DSS)
International Organization for Standardizations ג€" 27005 (ISO-27005)
Answer: A
5A security manager regularly checks work areas after business hours for security violations; such as unsecured files or unattended computers with active
sessions.
This activity BEST demonstrates what part of a security program?
Compliance management
Audit validation
Physical control testing
Security awareness training
Answer: A
6Which of the following is the MAIN reason to follow a formal risk management process in an organization that hosts and uses privately identifiable information (PII)
as part of their business models and processes?
Need to comply with breach disclosure laws
Fiduciary responsibility to safeguard credit information
Need to transfer the risk associated with hosting PII data
Need to better understand the risk associated with using PII data
Answer: D
7A method to transfer risk is to______________.
Implement redundancy
Move operations to another region
Align to business operations
Purchase breach insurance
Answer: D
8An organization licenses and uses personal information for business operations, and a server containing that information has been compromised.
What kind of law would require notifying the owner or licensee of this incident?
Consumer right disclosure
Data breach disclosure
Special circumstance disclosure
Security incident disclosure
Answer: B
9Why is it vitally important that senior management endorse a security policy?
So that employees will follow the policy directives.
So that they can be held legally accountable.
So that external bodies will recognize the organizations commitment to security.
So that they will accept ownership for security within the organization.
Answer: D
10Which of the following is of MOST importance when security leaders of an organization are required to align security to influence the culture of an organization?
Understand the business goals of the organization
Poses a strong technical background
Poses a strong auditing background
Understand all regulations affecting the organization