Free 512-50 Exam Braindumps (page: 38)

Page 37 of 102

The effectiveness of an audit is measured by?

  1. The number of actionable items in the recommendations
  2. How it exposes the risk tolerance of the company
  3. How the recommendations directly support the goals of the company
  4. The number of security controls the company has in use

Answer(s): C



A new CISO just started with a company and on the CISO's desk is the last complete Information Security Management audit report. The audit report is over two years old. After reading it, what should be the CISO's FIRST priority?

  1. Have internal audit conduct another audit to see what has changed.
  2. Contract with an external audit company to conduct an unbiased audit
  3. Review the recommendations and follow up to see if audit implemented the changes
  4. Meet with audit team to determine a timeline for corrections

Answer(s): C



You have implemented the new controls.
What is the next step?

  1. Document the process for the stakeholders
  2. Monitor the effectiveness of the controls
  3. Update the audit findings report
  4. Perform a risk assessment

Answer(s): B



An audit was conducted and many critical applications were found to have no disaster recovery plans in place. You conduct a Business Impact Analysis (BIA) to determine impact to the company for each application.
What should be the NEXT step?

  1. Determine the annual loss expectancy (ALE)
  2. Create a crisis management plan
  3. Create technology recovery plans
  4. Build a secondary hot site

Answer(s): C






Post your Comments and Discuss EC-Council 512-50 exam with other Community members:

512-50 Discussions & Posts