Free 712-50 Exam Braindumps (page: 7)

Page 6 of 115

Ensuring that the actions of a set of people, applications and systems follow the organization’s rules is BEST described as:

  1. Compliance management
  2. Security management
  3. Risk management
  4. Mitigation management

Answer(s): A



Which of the following international standards can be BEST used to define a Risk Management process in an organization?

  1. International Organization for Standardizations – 27005 (ISO-27005)
  2. National Institute for Standards and Technology 800-50 (NIST 800-50)
  3. Payment Card Industry Data Security Standards (PCI-DSS)
  4. International Organization for Standardizations – 27004 (ISO-27004)

Answer(s): A



A security professional has been promoted to be the CISO of an organization. The first task is to create a security policy for this organization. The CISO creates and publishes the security policy.

This policy, however, is ignored and not enforced consistently. Which of the following is the MOST likely reason for the policy shortcomings?

  1. Lack of a formal risk management policy
  2. Lack of a formal security policy governance process
  3. Lack of formal definition of roles and responsibilities
  4. Lack of a formal security awareness program

Answer(s): B



Regulatory requirements typically force organizations to implement_____________.

  1. Financial controls
  2. Mandatory controls
  3. Discretionary controls
  4. Optional controls

Answer(s): B






Post your Comments and Discuss EC-Council 712-50 exam with other Community members:

712-50 Exam Discussions & Posts