
100% Pass Your 712-50 Exam Dumps at First Attempt with Exam4Free
Penetration testers simulate 712-50 exam PDF
NEW QUESTION # 171
Your organization provides open guest wireless access with no captive portals. What can you do to assist with law enforcement investigations if one of your guests is suspected of committing an illegal act using your network?
- A. Configure logging on each access point
- B. Disable SSID Broadcast and enable MAC address filtering on all wireless access points.
- C. Install a firewall software on each wireless access point.
- D. Provide IP and MAC address
Answer: D
NEW QUESTION # 172
A security manager regualrly checks work areas after buisness hours for security violations; such as unsecured files or unattended computers with active sessions. This activity BEST demonstrates what part of a security program?
- A. Physical control testing
- B. Compliance management
- C. Security awareness training
- D. Audit validation
Answer: B
NEW QUESTION # 173
Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined security policy and framework for their Information Security Program. Your new boss, the Chief Financial Officer, has asked you to draft an outline of a security policy and recommend an industry/sector neutral information security control framework for implementation.
Which of the following industry / sector neutral information security control frameworks should you recommend for implementation?
- A. British Standard 7799 (BS7799)
- B. International Organization for Standardization - ISO 27001/2
- C. Payment Card Industry Digital Security Standard (PCI DSS)
- D. National Institute of Standards and Technology (NIST) Special Publication 800-53
Answer: B
Explanation:
Scenario2
NEW QUESTION # 174
Scenario: The new CISO was informed of all the Information Security projects that the section has in progress. Two projects are over a year behind schedule and way over budget.
Which of the following will be most helpful for getting an Information Security project that is behind schedule back on schedule?
- A. Involve internal audit
- B. More training of staff members
- C. More frequent project milestone meetings
- D. Upper management support
Answer: D
Explanation:
To get a delayed Information Security project back on track, upper management support is the most critical factor. Management endorsement provides authority, visibility, and potentially additional resources to overcome challenges.
* Role of Upper Management Support:
* Ensures prioritization of the project across the organization.
* Provides necessary resources, including budget and personnel.
* Helps remove obstacles and address inter-departmental dependencies.
* Other Options:
* More Frequent Meetings: Useful for tracking progress but doesn't address root causes.
* Staff Training: May be a factor but is not the primary solution.
* Involving Internal Audit: Helpful for oversight but less effective for immediate scheduling issues.
* Strategic Leadership in Projects: Stresses the importance of executive buy-in to resolve project delays.
* Project Governance: Highlights management support as a driver for success.
EC-Council CISO References:
Scenario10
NEW QUESTION # 175
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used as audit baselines. The audit report was presented to the CISO and a variety of high, medium and low rated gaps were identified.
Which of the following is the FIRST action the CISO will perform after receiving the audit report?
- A. Determine if security policies and procedures are adequate
- B. Create remediation plans to address program gaps
- C. Inform peer executives of the audit results
- D. Validate gaps and accept or dispute the audit findings
Answer: D
NEW QUESTION # 176
SCENARIO: A CISO has several two-factor authentication systems under review and selects the one that is most sufficient and least costly. The implementation project planning is completed and the teams are ready to implement the solution. The CISO then discovers that the product it is not as scalable as originally thought and will not fit the organization's needs.
The CISO discovers the scalability issue will only impact a small number of network segments. What is the next logical step to ensure the proper application of risk management methodology within the two-facto implementation project?
- A. Create new use cases for operational use of the solution
- B. Decide to accept the risk on behalf of the impacted business units
- C. Report the deficiency to the audit team and create process exceptions
- D. Determine if sufficient mitigating controls can be applied
Answer: D
Explanation:
If the scalability issue impacts only a small number of network segments, the next logical step is to determine if sufficient mitigating controls can address the issue without replacing the entire solution.
* Risk Assessment:
* Identifies the extent of the issue and potential mitigation strategies.
* Considers controls to reduce the impact on affected segments.
* Risk Mitigation:
* If feasible controls exist, they can minimize risk while retaining the original solution.
* Other Options:
* A: Use cases are secondary to resolving the core issue.
* C: Risk acceptance should only occur after exploring mitigation options.
* D: Reporting deficiencies to audit is procedural but does not address the risk.
* Risk Mitigation Strategies: Prioritizes applying controls to reduce risks to acceptable levels.
* Incident and Problem Management: Emphasizes minimizing operational impact through mitigation.
EC-Council CISO References:
Scenario8
NEW QUESTION # 177
A Chief Information Security Officer received a list of high, medium, and low impact audit findings.
Which of the following represents the BEST course of action?
- A. if the findings impact regulatory compliance, remediate the high findings as quickly as possible.
- B. If the findings impact regulatory compliance, try to apply remediation that will address the most findings for the least cost.
- C. If the findings do not impact regulatory compliance, remediate only the high and medium risk findings.
- D. If the findings do not impact regulatory compliance, review current security controls.
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION # 178
Scenario: An organization has recently appointed a CISO. This is a new role in the organization and it signals the increasing need to address security consistently at the enterprise level. This new CISO, while confident with skills and experience, is constantly on the defensive and is unable to advance the IT security centric agend a.
The CISO has been able to implement a number of technical controls and is able to influence the Information Technology teams but has not been able to influence the rest of the organization. From an organizational perspective, which of the following is the LIKELY reason for this?
- A. The CISO has not implemented a policy management framework
- B. The CISO reports to the IT organization
- C. The CISO does not report directly to the CEO of the organization
- D. The CISO has not implemented a security awareness program
Answer: B
NEW QUESTION # 179
A missing/ineffective security control is identified. Which of the following should be the NEXT step?
- A. Escalate the issue to the IT organization
- B. Perform a risk assessment to measure risk
- C. Establish Key Risk Indicators
- D. Perform an audit to measure the control formally
Answer: B
Explanation:
Next Step After Identifying a Missing Control:
* A risk assessment determines the potential impact and likelihood of the risk posed by the missing or ineffective control.
Purpose of the Assessment:
* This step quantifies the risk to prioritize and inform decision-making regarding mitigation strategies.
Supporting Reference:
* CCISO emphasizes risk assessment as a foundational step in addressing control gaps, ensuring risks are evaluated systematically.
NEW QUESTION # 180
What type of attack requires the least amount of technical equipment and has the highest success rate?
- A. Operating system attacks
- B. Shrink wrap attack
- C. War driving
- D. Social engineering
Answer: D
Explanation:
Definition of Social EngineeringSocial engineering is a non-technical attack method that manipulates human behavior to gain unauthorized access to information, systems, or physical locations. It typically exploits trust, ignorance, or carelessness.
Characteristics
* Least Equipment Needed: Social engineering often requires no more than communication tools (e.g., phone, email) or physical presence.
* Highest Success Rate: Human error is a common vulnerability, making this approach highly effective, especially when attackers exploit psychological triggers like urgency, fear, or curiosity.
Comparison of Options
* A. War driving: Requires equipment for detecting wireless networks and relies on the presence of weak Wi-Fi configurations.
* B. Operating system attacks: Involves identifying and exploiting OS vulnerabilities, requiring technical expertise and tools.
* D. Shrink wrap attack: Exploits default or unpatched software installations, requiring more specific conditions than social engineering.
EC-Council References
* CISO Insights: Social engineering attacks like phishing, pretexting, and baiting are consistently highlighted as major threats in EC-Council's curriculum.
* Incident Reports: Case studies in EC-Council's guidance show social engineering's prevalence and effectiveness across various sectors.
ConclusionSocial engineering, due to its simplicity and effectiveness in exploiting human behavior, is the attack type requiring the least technical equipment and yielding the highest success rate.
NEW QUESTION # 181
During the last decade, what trend has caused the MOST serious issues in relation to physical security?
- A. Data is more portable due to the increased use of smartphones and tablets
- B. The move from centralized computing to decentralized computing
- C. Camera systems have become more economical and expanded in their use
- D. The internet of Things allows easy compromise of cloud-based systems
Answer: A
NEW QUESTION # 182
John is the project manager for a large project in his organization. A new change request has been proposed that will affect several areas of the project. One area of the project change impact is on work that a vendor has already completed. The vendor is refusing to make the changes as they've already completed the project work they were contracted to do. What can John do in this instance?
- A. Refer the vendor to the Service Level Agreement (SLA) and insist that they make the changes.
- B. Refer to the contract agreement for direction.
- C. Withhold the vendor's payments until the issue is resolved.
- D. Review the Request for Proposal (RFP) for guidance.
Answer: B
Explanation:
When a vendor refuses to make changes after completing contracted work, the contract agreement serves as the binding document to resolve disputes and clarify obligations.
* Contractual Obligations:
* The agreement outlines the scope of work, responsibilities, and any clauses related to change management.
* Ensures both parties adhere to predefined terms.
* Steps to Resolve the Dispute:
* Review clauses about post-completion changes.
* Assess whether the requested changes fall within the vendor's contractual obligations.
* Why Other Options Are Less Suitable:
* SLA: Typically focuses on performance and service quality, not contract modifications.
* RFP: Pre-contract document, not applicable for resolving disputes.
* Withholding Payments: A punitive action that could escalate the conflict without resolving the issue.
* Vendor Management: Emphasizes the importance of clear contracts for managing vendor relationships and resolving conflicts.
* Legal and Compliance Guidance: Stresses adherence to contractual terms to ensure fairness and enforceability.
EC-Council CISO References:
NEW QUESTION # 183
The primary responsibility for assigning entitlements to a network share lies with which role?
- A. Data owner
- B. CISO
- C. Security system administrator
- D. Chief Information Officer (CIO)
Answer: A
Explanation:
* Role of Data Owner:
* The data owner is responsible for defining and assigning entitlements to access network shares or other data repositories.
* They establish permissions based on business needs and sensitivity of the data.
* Why Not Other Options:
* A: The CISO sets security policies but does not manage specific entitlements.
* C: The CIO oversees IT strategy but typically delegates entitlement assignments to data owners.
* D: Security system administrators implement permissions but do not define them.
Reference:
Infosec Institute on Data Ownership and Entitlement Assignment
Reference: https://resources.infosecinstitute.com/certification/data-and-system-ownership/
NEW QUESTION # 184
When gathering security requirements for an automated business process improvement program, which of the following is MOST important?
- A. Type of encryption required for the data once it is at rest
- B. Type of connection/protocol used to transfer the data
- C. Type of data contained in the process/system
- D. Type of computer the data is processed on
Answer: C
NEW QUESTION # 185
A CISO implements smart cards for credential management, and as a result has reduced costs associated with help desk operations supporting password resets. This demonstrates which of the following principles?
- A. Increased security program presence
- B. Proper organizational policy enforcement
- C. Regulatory compliance effectiveness
- D. Security alignment to business goals
Answer: D
NEW QUESTION # 186
Knowing the potential financial loss an organization is willing to suffer if a system fails is a determination of which of the following?
- A. Business continuity
- B. Risk appetite
- C. Cost benefit
- D. Likelihood of impact
Answer: B
NEW QUESTION # 187
What is the primary reason for performing vendor management?
- A. To establish a vendor selection process
- B. To document the relationship between the company and vendor
- C. To understand the risk coverage that are being mitigated by the vendor
- D. To define the partnership for long-term success
Answer: C
NEW QUESTION # 188
Which of the following methods are used to define contractual obligations that force a vendor to meet customer expectations?
- A. Key Performance Indicators (KPI)
- B. Terms and Conditions
- C. Statement of Work
- D. Service Level Agreements (SLA)
Answer: D
NEW QUESTION # 189
The PRIMARY objective of security awareness is to:
- A. Encourage security-conscious behavior
- B. Put employees on notice in case follow-up action for noncompliance is necessary
- C. Ensure that security policies are read.
Answer: A
NEW QUESTION # 190
Creating good security metrics is essential for a CISO. What would be the BEST sources for creating security metrics for baseline defenses coverage?
- A. Firewall, anti-virus console, IDS, syslog
- B. IDS, syslog, router, switches
- C. Servers, routers, switches, modem
- D. Firewall, exchange, web server, intrusion detection system (IDS)
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION # 191
Which of the following activities results in change requests?
- A. Inspection
- B. Corrective actions
- C. Preventive actions
- D. Defect repair
Answer: C
NEW QUESTION # 192
Regulatory requirements typically force organizations to implement
- A. Discretionary controls
- B. Financial controls
- C. Mandatory controls
- D. Optional controls
Answer: C
NEW QUESTION # 193
The amount of risk an organization is willing to accept in pursuit of its mission is known as______________.
- A. risk tolerance
- B. risk transfer
- C. risk acceptance
- D. risk mitigation
Answer: A
NEW QUESTION # 194
When selecting a security solution with reoccurring maintenance costs after the first year (choose the BEST answer):
- A. Implement the solution and ask for the increased operating cost budget when it is time
- B. The CISO should cut other essential programs to ensure the new solution's continued use
- C. Defer selection until the market improves and cash flow is positive
- D. Communicate future operating costs to the CIO/CFO and seek commitment from them to ensure the new solution's continued use
Answer: D
NEW QUESTION # 195
......
All 712-50 Dumps and Training Courses: https://www.exam4free.com/712-50-valid-dumps.html
Help candidates to study and pass the EC-Council Certified CISO (CCISO) Exams hassle-free: https://drive.google.com/open?id=1kUPk_Fac3wN1G1DdWN3HqTUSHeAv8KEP
