Free 512-50 Exam Braindumps (page: 6)

Page 5 of 102

Which of the following is the MAIN reason to follow a formal risk management process in an organization that hosts and uses privately identifiable information (PII) as part of their business models and processes?

  1. Need to comply with breach disclosure laws
  2. Need to transfer the risk associated with hosting PII data
  3. Need to better understand the risk associated with using PII data
  4. Fiduciary responsibility to safeguard credit card information

Answer(s): C



The alerting, monitoring and life-cycle management of security related events is typically handled by the

  1. security threat and vulnerability management process
  2. risk assessment process
  3. risk management process
  4. governance, risk, and compliance tools

Answer(s): A



One of the MAIN goals of a Business Continuity Plan is to

  1. Ensure all infrastructure and applications are available in the event of a disaster
  2. Allow all technical first-responders to understand their roles in the event of a disaster
  3. Provide step by step plans to recover business processes in the event of a disaster
  4. Assign responsibilities to the technical teams responsible for the recovery of all data.

Answer(s): C



When managing an Information Security Program, which of the following is of MOST importance in order to influence the culture of an organization?

  1. An independent Governance, Risk and Compliance organization
  2. Alignment of security goals with business goals
  3. Compliance with local privacy regulations
  4. Support from Legal and HR teams

Answer(s): B






Post your Comments and Discuss EC-Council 512-50 exam with other Community members:

512-50 Discussions & Posts