Free 512-50 Exam Braindumps (page: 5)

Page 4 of 102

From an information security perspective, information that no longer supports the main purpose of the business should be:

  1. assessed by a business impact analysis.
  2. protected under the information classification policy.
  3. analyzed under the data ownership policy.
  4. analyzed under the retention policy

Answer(s): D



When briefing senior management on the creation of a governance process, the MOST important aspect should be:

  1. information security metrics.
  2. knowledge required to analyze each issue.
  3. baseline against which metrics are evaluated.
  4. linkage to business area objectives.

Answer(s): D



Which of the following most commonly falls within the scope of an information security governance steering committee?

  1. Approving access to critical financial systems
  2. Developing content for security awareness programs
  3. Interviewing candidates for information security specialist positions
  4. Vetting information security policies

Answer(s): D



A security professional has been promoted to be the CISO of an organization. The first task is to create a security policy for this organization. The CISO creates and publishes the security policy. This policy however, is ignored and not enforced consistently.
Which of the following is the MOST likely reason for the policy shortcomings?

  1. Lack of a formal security awareness program
  2. Lack of a formal security policy governance process
  3. Lack of formal definition of roles and responsibilities
  4. Lack of a formal risk management policy

Answer(s): B






Post your Comments and Discuss EC-Council 512-50 exam with other Community members:

512-50 Discussions & Posts