Free 512-50 Exam Braindumps (page: 43)

Page 42 of 102

Which of the following is the PRIMARY purpose of International Organization for Standardization (ISO) 27001?

  1. Use within an organization to formulate security requirements and objectives
  2. Implementation of business-enabling information security
  3. Use within an organization to ensure compliance with laws and regulations
  4. To enable organizations that adopt it to obtain certifications

Answer(s): B



The MOST common method to get an unbiased measurement of the effectiveness of an Information Security Management System (ISMS) is to

  1. assign the responsibility to the information security team.
  2. assign the responsibility to the team responsible for the management of the controls.
  3. create operational reports on the effectiveness of the controls.
  4. perform an independent audit of the security controls.

Answer(s): D



The effectiveness of social engineering penetration testing using phishing can be used as a Key Performance Indicator (KPI) for the effectiveness of an organization's

  1. Risk Management Program.
  2. Anti-Spam controls.
  3. Security Awareness Program.
  4. Identity and Access Management Program.

Answer(s): C



Which of the following is the MOST important reason to measure the effectiveness of an Information Security Management System (ISMS)?

  1. Meet regulatory compliance requirements
  2. Better understand the threats and vulnerabilities affecting the environment
  3. Better understand strengths and weaknesses of the program
  4. Meet legal requirements

Answer(s): C






Post your Comments and Discuss EC-Council 512-50 exam with other Community members:

512-50 Discussions & Posts