
[Apr 18, 2024] Reliable 712-50 Exam Tips Test Pdf Exam Material
New 2024 712-50 Test Tutorial (Updated 447 Questions)
NEW QUESTION # 232
Dataflow diagrams are used by IT auditors to:
- A. Order data hierarchically.
- B. Graphically summarize data paths and storage processes.
- C. Highlight high-level data definitions.
- D. Portray step-by-step details of data generation.
Answer: B
NEW QUESTION # 233
The CIO of an organization has decided to assign the responsibility of internal IT audit to the IT team. This is consider a bad practice MAINLY because
- A. This represents a bad implementation of the Least Privilege principle
- B. The IT team is not familiar in IT audit practices
- C. This represents a conflict of interest
- D. The IT team is not certified to perform audits
Answer: C
NEW QUESTION # 234
Which is the BEST solution to monitor, measure, and report changes to critical data in a system?
- A. Application logs
- B. Syslog
- C. SNMP traps
- D. File integrity monitoring
Answer: D
NEW QUESTION # 235
A method to transfer risk is to:
- A. purchase breach insurance
- B. Implement redundancy
- C. Alignment with business operations
- D. move operations to another region
Answer: A
NEW QUESTION # 236
The general ledger setup function in an enterprise resource package allows for setting accounting periods.
Access to this function has been permitted to users in finance, the shipping department, and production scheduling.
What is the most likely reason for such broad access?
- A. The need to change accounting periods on a regular basis.
- B. The lack of policies and procedures for the proper segregation of duties.
- C. The need to create and modify the chart of accounts and its allocations.
- D. The requirement to post entries for closed accounting period.
Answer: B
NEW QUESTION # 237
An organization's firewall technology needs replaced. A specific technology has been selected that is less costly than others and lacking in some important capabilities. The security officer has voiced concerns about sensitive data breaches but the decision is made to purchase.
What does this selection indicate?
- A. A high risk tolerance environment
- B. I low vulnerability environment
- C. A high threat environment
- D. A low risk tolerance environment
Answer: A
NEW QUESTION # 238
The executive board has requested that the CISO of an organization define and Key Performance Indicators (KPI) to measure the effectiveness of the security awareness program provided to call center employees.
Which of the following can be used as a KPI?
- A. Number of callers who report security issues.
- B. Number of successful social engineering attempts on the call center
- C. Number of callers who report a lack of customer service from the call center
- D. Number of callers who abandon the call before speaking with a representative
Answer: B
NEW QUESTION # 239
When creating contractual agreements and procurement processes why should security requirements be included?
- A. To make sure the costs of security is included and understood
- B. To make sure they are added on after the process is completed
- C. To make sure the patching process is included with the costs
- D. To make sure the security process aligns with the vendor's security process
Answer: A
Explanation:
Scenario1
NEW QUESTION # 240
Which of the following are necessary to formulate responses to external audit findings?
- A. Technical Staff, Budget Authority, Management
- B. Internal Audit, Management, and Technical Staff
- C. Technical Staff, Internal Audit, Budget Authority
- D. Internal Audit, Budget Authority, Management
Answer: A
NEW QUESTION # 241
Many times a CISO may have to speak to the Board of Directors (BOD) about their cyber security posture. What would be the BEST choice of security metrics to present to the BOD?
- A. Only critical and high vulnerabilities on servers and desktops
- B. All vulnerabilities that impact important production servers
- C. Only critical and high vulnerabilities that impact important production servers
- D. All vulnerabilities found on servers and desktops
Answer: C
NEW QUESTION # 242
Scenario: Your program is developed around minimizing risk to information by focusing on people, technology, and operations.
An effective way to evaluate the effectiveness of an information security awareness program for end users, especially senior executives, is to conduct periodic:
- A. Scanning for viruses
- B. Password changes
- C. Controlled spear phishing campaigns
- D. Baseline of computer systems
Answer: C
NEW QUESTION # 243
Payment Card Industry (PCI) compliance requirements are based on what criteria?
- A. The size of the organization processing credit card data
- B. The number of transactions performed per year by an organization
- C. The duration card holder data is retained
- D. The types of cardholder data retained
Answer: B
NEW QUESTION # 244
You have implemented a new security control. Which of the following risk strategy options have you engaged in?
- A. Risk Avoidance
- B. Risk Mitigation
- C. Risk Acceptance
- D. Risk Transfer
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION # 245
A CISO implements smart cards for credential management, and as a result has reduced costs associated with help desk operations supporting password resets.
This demonstrates which of the following principles?
- A. Increased security program presence
- B. Proper organizational policy enforcement
- C. Security organizational policy enforcement
- D. Regulatory compliance effectiveness
Answer: C
NEW QUESTION # 246
As the CISO you need to write the IT security strategic plan.
Which of the following is the MOST important to review before you start writing the plan?
- A. The company business plan
- B. The present IT budget
- C. Other corporate technology trends
- D. The existing IT environment
Answer: A
NEW QUESTION # 247
Which of the following reports should you as an IT auditor use to check on compliance with a service level agreement's requirement for uptime?
- A. Hardware error reports
- B. Availability reports
- C. Utilization reports
- D. Systems logs
Answer: B
NEW QUESTION # 248
When an organization claims it is secure because it is PCI-DSS certified, what is a good first question to ask towards assessing the effectiveness of their security program?
- A. What is the value of the assets at risk?
- B. How many credit card records are stored?
- C. What is the scope of the certification?
- D. How many servers do you have?
Answer: C
NEW QUESTION # 249
An organization information security policy serves to___________________.
- A. establish acceptable systems and user behavior
- B. None
- C. define relationships with external law enforcement agencies
- D. establish budgetary input in order to meet compliance requirements
- E. define security configurations for systems
Answer: A
NEW QUESTION # 250
Which of the following is the MOST important reason to measure the effectiveness of an Information Security Management System (ISMS)?
- A. Meet regulatory compliance requirements
- B. Better understand strengths and weaknesses of the program
- C. Meet legal requirements
- D. Better understand the threats and vulnerabilities affecting the environment
Answer: B
NEW QUESTION # 251
In accordance with best practices and international standards, how often is security awareness training provided to employees of an organization?
- A. High risk environments 6 months, low-risk environments 12 months
- B. Every 12 months
- C. Every 18 months
- D. Every 6 months
Answer: B
NEW QUESTION # 252
Which of the following would negatively impact a log analysis of a multinational organization?
- A. Centralized log management
- B. Each node set to local time
- C. Log aggregation agent each node
- D. Encrypted log files in transit
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION # 253
Information Security is often considered an excessive, after-the-fact cost when a project or initiative is completed.
What can be done to ensure that security is addressed cost effectively?
- A. Installation of new firewalls and intrusion detection systems
- B. Integrate security requirements into project inception
- C. Launch an internal awareness campaign
- D. User awareness training for all employees
Answer: B
NEW QUESTION # 254
......
712-50 Cert Guide PDF 100% Cover Real Exam Questions: https://www.easy4engine.com/712-50-test-engine.html
712-50 Exam Questions Dumps, Selling EC-COUNCIL Products: https://drive.google.com/open?id=1f7069V2jvYY-ucdyFdlV3zielDQBJJ7J

