無料で使える712-50試験ブレーン問題集認定ガイド問題と解答 [Q31-Q51]

Share

無料で使える712-50試験ブレーン問題集認定ガイド問題と解答

712-50認定概要最新の712-50のPDF問題集


CCISO認定試験は、自己の組織内でセキュリティプログラムを管理および実装する責任を持つ経験豊富な情報セキュリティ専門家を対象に設計されています。認定試験は、統治とリスク管理、情報セキュリティコントロールと監査管理、セキュリティプログラム管理と運用、情報セキュリティの基本的な概念、戦略的計画と財務の5つのドメインをカバーしています。試験は、これらのドメインの知識と理解力、および実際の現場での適用能力をテストするよう設計されています。


CCISO認定試験は、4時間の時間枠内に完了する必要がある150の複数選択質問で構成されています。この試験では、リスク評価と管理、セキュリティ管理、コンプライアンス、インシデント対応、災害復旧など、情報セキュリティ管理に関連する幅広いトピックをカバーしています。

 

質問 # 31
An employee successfully avoids becoming a victim of a sophisticated spear phishing attack due to knowledge gained through the corporate information security awareness program. What type of control has been effectively utilized?

  • A. Training Control
  • B. Technical Control
  • C. Management Control
  • D. Operational Control

正解:D


質問 # 32
A global retail company is creating a new compliance management process. Which of the following regulations is of MOST importance to be tracked and managed by this process?

  • A. National Institute for Standards and Technology (NIST) standard
  • B. Information Technology Infrastructure Library (ITIL)
  • C. Payment Card Industry Data Security Standards (PCI-DSS)
  • D. International Organization for Standardization (ISO) standards

正解:C


質問 # 33
The executive board has requested that the CISO of an organization define and Key Performance Indicators (KPI) to measure the effectiveness of the security awareness program provided to call center employees.
Which of the following can be used as a KPI?

  • A. Number of callers who report security issues.
  • B. Number of successful social engineering attempts on the call center
  • C. Number of callers who report a lack of customer service from the call center
  • D. Number of callers who abandon the call before speaking with a representative

正解:B

解説:
Explanation/Reference:


質問 # 34
What is the MAIN reason for conflicts between Information Technology and Information Security programs?

  • A. Security governance defines technology best practices and Information Technology governance does not.
  • B. Technology Governance is focused on process risks whereas Security Governance is focused on business risk.
  • C. The effective implementation of security controls can be viewed as an inhibitor to rapid Information technology implementations.
  • D. Technology governance defines technology policies and standards while security governance does not.

正解:C


質問 # 35
Scenario: An organization has recently appointed a CISO. This is a new role in the organization and it signals the increasing need to address security consistently at the enterprise level. This new CISO, while confident with skills and experience, is constantly on the defensive and is unable to advance the IT security centric agenda.
Which of the following is the reason the CISO has not been able to advance the security agenda in this organization?

  • A. Lack of influence with leaders outside IT
  • B. Lack of business continuity process
  • C. Lack of identification of technology stake holders
  • D. Lack of a security awareness program

正解:A


質問 # 36
Which of the following is of MOST importance when security leaders of an organization are required to align security to influence the culture of an organization?

  • A. Poses a strong technical background
  • B. Understand all regulations affecting the organization
  • C. Understand the business goals of the organization
  • D. Poses a strong auditing background

正解:C


質問 # 37
What organizational structure combines the functional and project structures to create a hybrid of the two?

  • A. Matrix
  • B. Project
  • C. Traditional
  • D. Composite

正解:A


質問 # 38
Creating a secondary authentication process for network access would be an example of?

  • A. Network segmentation.
  • B. An administrator with too much time on their hands.
  • C. Supporting the concept of layered security
  • D. Putting undue time commitment on the system administrator.

正解:C


質問 # 39
Which of the following has the GREATEST impact on the implementation of an information security governance model?

  • A. Number of employees
  • B. Organizational budget
  • C. Distance between physical locations
  • D. Complexity of organizational structure

正解:D


質問 # 40
Which of the following would negatively impact a log analysis of a multinational organization?

  • A. Centralized log management
  • B. Each node set to local time
  • C. Encrypted log files in transit
  • D. Log aggregation agent each node

正解:D


質問 # 41
Creating a secondary authentication process for network access would be an example of?

  • A. Network segmentation.
  • B. An administrator with too much time on their hands.
  • C. Supporting the concept of layered security
  • D. Putting undue time commitment on the system administrator.

正解:C


質問 # 42
What is the BEST reason for having a formal request for proposal process?

  • A. Clearly identifies risks and benefits before funding is spent
  • B. Allows small companies to compete with larger companies
  • C. Creates a timeline for purchasing and budgeting
  • D. Informs suppliers a company is going to make a purchase

正解:A


質問 # 43
In accordance with best practices and international standards, how often is security awareness training provided to employees of an organization?

  • A. Every 12 months
  • B. High risk environments 6 months, low-risk environments 12 months
  • C. Every 18 months
  • D. Every 6 months

正解:A


質問 # 44
How often should the Statements of Standards for Attestation Engagements-16 (SSAE16)/International Standard on Assurance Engagements 3402 (ISAE3402) report of your vendors be reviewed?

  • A. Semi-annually
  • B. Bi-annually
  • C. Annually
  • D. Quarterly

正解:C


質問 # 45
Scenario: An organization has recently appointed a CISO. This is a new role in the organization and it signals the increasing need to address security consistently at the enterprise level. This new CISO, while confident with skills and experience, is constantly on the defensive and is unable to advance the IT security centric agenda.
Which of the following is the reason the CISO has not been able to advance the security agenda in this organization?

  • A. Lack of influence with leaders outside IT
  • B. Lack of business continuity process
  • C. Lack of identification of technology stake holders
  • D. Lack of a security awareness program

正解:A


質問 # 46
A CISO sees abnormally high volumes of exceptions to security requirements and constant pressure from business units to change security processes. Which of the following represents the MOST LIKELY cause of this situation?

  • A. A lack of executive presence within the security program
  • B. Poor audit support for the security program
  • C. Poor alignment of the security program to business needs
  • D. This is normal since business units typically resist security requirements

正解:C


質問 # 47
In order for a CISO to have true situational awareness there is a need to deploy technology that can give a real-time view of security events across the enterprise.
Which tool selection represents the BEST choice to achieve situational awareness?

  • A. VMware, router, switch, firewall, syslog, vulnerability management system (VMS)
  • B. Intrusion Detection System (IDS), firewall, switch, syslog
  • C. SIEM, IDS, firewall, VMSSIEM, IDS, firewall, VMS
  • D. Security Incident Event Management (SIEM), IDS, router, syslog

正解:C


質問 # 48
When analyzing and forecasting a capital expense budget what are not included?

  • A. Purchase of new mobile devices to improve operations
  • B. Upgrade of mainframe
  • C. Network connectivity costs
  • D. New datacenter to operate from

正解:C


質問 # 49
After a risk assessment is performed, a particular risk is considered to have the potential of costing the organization 1.2 Million USD. This is an example of

  • A. Quantitative risk analysis
  • B. Risk Tolerance
  • C. Qualitative risk analysis
  • D. Risk Appetite

正解:A


質問 # 50
A person in your security team calls you at night and informs you that one of your web applications is potentially under attack from a cross-site scripting vulnerability. What do you do?

  • A. tell him to analyze the problem, preserve the evidence and provide a full analysis and report
  • B. tell him to call the police
  • C. tell him to shut down the server
  • D. tell him to invoke the incident response process

正解:D


質問 # 51
......


EC-COUNCIL 712-50 試験は、情報セキュリティ管理に関連するさまざまな分野での知識やスキルを証明することを求められる、厳格でチャレンジングな試験です。この試験は、セキュリティガバナンス、リスク管理、コンプライアンス、戦略的計画、財務管理などのトピックをカバーしています。受験者は、各分野についての深い理解を証明して、試験に合格し、CCISO認定を取得する必要があります。

 

ベストなEC-COUNCIL 712-50学習ガイドと問題集には2024:https://www.jpntest.com/shiken/712-50-mondaishu

トップクラスEC-COUNCIL 712-50試験材料で学習ガイド!練習問題バージョンで挑もう:https://drive.google.com/open?id=1X19CniE2b0YgTB1LyrWHgyG4TR9U993l

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡