Free 712-50 Exam Braindumps (page: 6)

Page 5 of 115

When managing an Information Security Program, which of the following is of MOST importance in order to influence the culture of an organization?

  1. Compliance with local privacy regulations
  2. An independent Governance, Risk and Compliance organization
  3. Support Legal and HR teams
  4. Alignment of security goals with business goals

Answer(s): D



The FIRST step in establishing a security governance program is to?

  1. Obtain senior level sponsorship
  2. Conduct a workshop for all end users.
  3. Conduct a risk assessment.
  4. Prepare a security budget.

Answer(s): A



When an organization claims it is secure because it is PCI-DSS certified, what is a good first question to ask towards assessing the effectiveness of their security program?

  1. How many credit records are stored?
  2. What is the value of the assets at risk?
  3. What is the scope of the certification?
  4. How many servers do you have?

Answer(s): C



A security manager has created a risk program. Which of the following is a critical part of ensuring the program is successful?

  1. Ensuring developers include risk control comments in code
  2. Creating risk assessment templates based on specific threats
  3. Providing a risk program governance structure
  4. Allowing for the acceptance of risk for regulatory compliance requirements

Answer(s): C






Post your Comments and Discuss EC-Council 712-50 exam with other Community members:

712-50 Exam Discussions & Posts