Pass the ECCouncil CCISO 712-50 Questions and answers with CertsForce

Viewing page 4 out of 14 pages
Viewing questions 31-40 out of questions
Questions # 31:

What is a key policy that should be part of the information security plan?

Options:

A.

Account management policy


B.

Training policy


C.

Acceptable Use policy


D.

Remote Access policy


Expert Solution
Questions # 32:

Which of the following is considered the MOST effective tool against social engineering?

Options:

A.

Anti-phishing tools


B.

Effective Security awareness program


C.

Anti-malware tools


D.

Effective Security Vulnerability Management Program


Expert Solution
Questions # 33:

When obtaining new products and services, why is it essential to collaborate with lawyers, IT security professionals, privacy professionals, security engineers, suppliers, and others?

Options:

A.

This makes sure the files you exchange aren’t unnecessarily flagged by the Data Loss Prevention (DLP) system


B.

Contracting rules typically require you to have conversations with two or more groups


C.

Discussing decisions with a very large group of people always provides a better outcome


D.

It helps to avoid regulatory or internal compliance issues


Expert Solution
Questions # 34:

The Board of Directors of a publicly-traded company is concerned about the security implications of a strategic project that will migrate 50% of the organization’s information technology assets to the cloud. They have requested a briefing on the project plan and a progress report of the security stream of the project. As the CISO, you have been tasked with preparing the report for the Chief Executive Officer to present.

Using the Earned Value Management (EVM), what does a Cost Variance (CV) of -1,200 mean?

Options:

A.

The project is over budget


B.

The project budget has reserves


C.

The project cost is in alignment with the budget


D.

The project is under budget


Expert Solution
Questions # 35:

Which of the following statements below regarding Key Performance indicators (KPIs) are true?

Options:

A.

Development of KPI’s are most useful when done independently


B.

They are a strictly quantitative measure of success


C.

They should be standard throughout the organization versus domain-specific so they are more easily correlated


D.

They are a strictly qualitative measure of success


Expert Solution
Questions # 36:

Which of the following is the MOST important to share with an Information Security Steering Committee:

Options:

A.

Include a mix of members from different departments and staff levels


B.

Review audit and compliance reports


C.

Ensure that security policies and procedures have been vetted and approved


D.

Be briefed about new trends and products at each meeting by a vendor


Expert Solution
Questions # 37:

A Security Operations (SecOps) Manager is considering implementing threat hunting to be able to make better decisions on protecting information and assets.

What is the MAIN goal of threat hunting to the SecOps Manager?

Options:

A.

Improve discovery of valid detected events


B.

Enhance tuning of automated tools to detect and prevent attacks


C.

Replace existing threat detection strategies


D.

Validate patterns of behavior related to an attack


Expert Solution
Questions # 38:

An auditor is reviewing the security classifications for a group of assets and finds that many of the assets are not correctly classified.

What should the auditor’s NEXT step be?

Options:

A.

Immediately notify the board of directors of the organization as to the finding


B.

Correct the classifications immediately based on the auditor’s knowledge of the proper classification


C.

Document the missing classifications


D.

Identify the owner of the asset and induce the owner to apply a proper classification


Expert Solution
Questions # 39:

A cloud computing environment that is bound together by technology that allows data and applications to be shared between public and private clouds is BEST referred to as a?

Options:

A.

Public cloud


B.

Private cloud


C.

Community cloud


D.

Hybrid cloud


Expert Solution
Questions # 40:

What does RACI stand for?

Options:

A.

Reasonable, Actionable, Controlled, and Implemented


B.

Responsible, Actors, Consult, and Instigate


C.

Responsible, Accountable, Consulted, and Informed


D.

Review, Act, Communicate, and Inform


Expert Solution
Viewing page 4 out of 14 pages
Viewing questions 31-40 out of questions