Free 512-50 Exam Braindumps (page: 45)

Page 44 of 102

Which of the following represents the BEST reason for an organization to use the Control Objectives for Information and Related Technology (COBIT) as an Information Technology (IT) framework?

  1. It allows executives to more effectively monitor IT implementation costs
  2. Implementation of it eases an organization's auditing and compliance burden
  3. Information Security (IS) procedures often require augmentation with other standards
  4. It provides for a consistent and repeatable staffing model for technology organizations

Answer(s): B



You are the Chief Information Security Officer of a large, multinational bank and you suspect there is a flaw in a two factor authentication token management process.
Which of the following represents your BEST course of action?

  1. Validate that security awareness program content includes information about the potential vulnerability
  2. Conduct a thorough risk assessment against the current implementation to determine system functions
  3. Determine program ownership to implement compensating controls
  4. Send a report to executive peers and business unit owners detailing your suspicions

Answer(s): B



Who is responsible for verifying that audit directives are implemented?

  1. IT Management
  2. Internal Audit
  3. IT Security
  4. BOD Audit Committee

Answer(s): B


Reference:

https://www.eccouncil.org/information-security-management/



A person in your security team calls you at night and informs you that one of your web applications is potentially under attack from a cross-site scripting vulnerability.
What do you do?

  1. tell him to shut down the server
  2. tell him to call the police
  3. tell him to invoke the incident response process
  4. tell him to analyze the problem, preserve the evidence and provide a full analysis and report

Answer(s): C






Post your Comments and Discuss EC-Council 512-50 exam with other Community members:

512-50 Discussions & Posts