Pass the ECCouncil CCISO 712-50 Questions and answers with CertsForce

Viewing page 10 out of 14 pages
Viewing questions 91-100 out of questions
Questions # 91:

What should an organization do to ensure that they have a sound Business Continuity (BC) Plan?

Options:

A.

Test every three years to ensure that things work as planned


B.

Conduct periodic tabletop exercises to refine the BC plan


C.

Outsource the creation and execution of the BC plan to a third party vendor


D.

Conduct a Disaster Recovery (DR) exercise every year to test the plan


Expert Solution
Questions # 92:

Which of the following activities must be completed BEFORE you can calculate risk?

Options:

A.

Determining the likelihood that vulnerable systems will be attacked by specific threats


B.

Calculating the risks to which assets are exposed in their current setting


C.

Assigning a value to each information asset


D.

Assessing the relative risk facing the organization’s information assets


Expert Solution
Questions # 93:

Which of the following provides an audit framework?

Options:

A.

Control Objectives for IT (COBIT)


B.

Payment Card Industry-Data Security Standard (PCI-DSS)


C.

International Organization Standard (ISO) 27002


D.

National Institute of Standards and Technology (NIST) SP 800-30


Expert Solution
Questions # 94:

Payment Card Industry (PCI) compliance requirements are based on what criteria?

Options:

A.

The types of cardholder data retained


B.

The duration card holder data is retained


C.

The size of the organization processing credit card data


D.

The number of transactions performed per year by an organization


Expert Solution
Questions # 95:

Which of the following has the GREATEST impact on the implementation of an information security governance model?

Options:

A.

Organizational budget


B.

Distance between physical locations


C.

Number of employees


D.

Complexity of organizational structure


Expert Solution
Questions # 96:

Which of the following tests is an IS auditor performing when a sample of programs is selected to determine if the source and object versions are the same?

Options:

A.

A substantive test of program library controls


B.

A compliance test of program library controls


C.

A compliance test of the program compiler controls


D.

A substantive test of the program compiler controls


Expert Solution
Questions # 97:

Which of the following is a critical operational component of an Incident Response Program (IRP)?

Options:

A.

Weekly program budget reviews to ensure the percentage of program funding remains constant.


B.

Annual review of program charters, policies, procedures and organizational agreements.


C.

Daily monitoring of vulnerability advisories relating to your organization’s deployed technologies.


D.

Monthly program tests to ensure resource allocation is sufficient for supporting the needs of the organization


Expert Solution
Questions # 98:

Regulatory requirements typically force organizations to implement

Options:

A.

Mandatory controls


B.

Discretionary controls


C.

Optional controls


D.

Financial controls


Expert Solution
Questions # 99:

Which of the following is a weakness of an asset or group of assets that can be exploited by one or more threats?

Options:

A.

Threat


B.

Vulnerability


C.

Attack vector


D.

Exploitation


Expert Solution
Questions # 100:

Which of the following is MOST important when dealing with an Information Security Steering committee:

Options:

A.

Include a mix of members from different departments and staff levels.


B.

Ensure that security policies and procedures have been vetted and approved.


C.

Review all past audit and compliance reports.


D.

Be briefed about new trends and products at each meeting by a vendor.


Expert Solution
Viewing page 10 out of 14 pages
Viewing questions 91-100 out of questions