Free 512-50 Exam Braindumps (page: 15)

Page 14 of 102

An organization licenses and uses personal information for business operations, and a server containing that information has been compromised.
What kind of law would require notifying the owner or licensee of this incident?

  1. Data breach disclosure
  2. Consumer right disclosure
  3. Security incident disclosure
  4. Special circumstance disclosure

Answer(s): A



An organization's firewall technology needs replaced. A specific technology has been selected that is less costly than others and lacking in some important capabilities. The security officer has voiced concerns about sensitive data breaches but the decision is made to purchase.
What does this selection indicate?

  1. A high threat environment
  2. A low risk tolerance environment
  3. I low vulnerability environment
  4. A high risk tolerance environment

Answer(s): D



An organization has defined a set of standard security controls. This organization has also defined the circumstances and conditions in which they must be applied.
What is the NEXT logical step in applying the controls in the organization?

  1. Determine the risk tolerance
  2. Perform an asset classification
  3. Create an architecture gap analysis
  4. Analyze existing controls on systems

Answer(s): B



A security manager has created a risk program.
Which of the following is a critical part of ensuring the program is successful?

  1. Providing a risk program governance structure
  2. Ensuring developers include risk control comments in code
  3. Creating risk assessment templates based on specific threats
  4. Allowing for the acceptance of risk for regulatory compliance requirements

Answer(s): A






Post your Comments and Discuss EC-Council 512-50 exam with other Community members:

512-50 Discussions & Posts