EC-Council 512-50 Exam Questions
Information Security Manager (Page 13 )

Updated On: 17-Feb-2026

A security manager has created a risk program.
Which of the following is a critical part of ensuring the program is successful?

  1. Providing a risk program governance structure
  2. Ensuring developers include risk control comments in code
  3. Creating risk assessment templates based on specific threats
  4. Allowing for the acceptance of risk for regulatory compliance requirements

Answer(s): A



Which of the following international standards can be BEST used to define a Risk Management process in an organization?

  1. National Institute for Standards and Technology 800-50 (NIST 800-50)
  2. International Organization for Standardizations ­ 27005 (ISO-27005)
  3. Payment Card Industry Data Security Standards (PCI-DSS)
  4. International Organization for Standardizations ­ 27004 (ISO-27004)

Answer(s): B



An organization is looking for a framework to measure the efficiency and effectiveness of their Information Security Management System.
Which of the following international standards can BEST assist this organization?

  1. International Organization for Standardizations ­ 27004 (ISO-27004)
  2. Payment Card Industry Data Security Standards (PCI-DSS)
  3. Control Objectives for Information Technology (COBIT)
  4. International Organization for Standardizations ­ 27005 (ISO-27005)

Answer(s): A



A global retail company is creating a new compliance management process.
Which of the following regulations is of MOST importance to be tracked and managed by this process?

  1. Information Technology Infrastructure Library (ITIL)
  2. International Organization for Standardization (ISO) standards
  3. Payment Card Industry Data Security Standards (PCI-DSS)
  4. National Institute for Standards and Technology (NIST) standard

Answer(s): C



A global retail organization is looking to implement a consistent Disaster Recovery and Business Continuity Process across all of its business units.
Which of the following standards and guidelines can BEST address this organization's need?

  1. International Organization for Standardizations ­ 22301 (ISO-22301)
  2. Information Technology Infrastructure Library (ITIL)
  3. Payment Card Industry Data Security Standards (PCI-DSS)
  4. International Organization for Standardizations ­ 27005 (ISO-27005)

Answer(s): A






Post your Comments and Discuss EC-Council 512-50 exam dumps with other Community members:

Join the 512-50 Discussion