
[2025年06月]更新の712-50試験資料EC-COUNCIL学習ガイド
有効な問題最新版を試そう712-50テスト解釈712-50有効な試験ガイド
EC-Council Certified CISO(CCISO)試験は、企業全体の情報セキュリティプログラムの管理、設計、および実装におけるエグゼクティブレベルのセキュリティ専門家の専門知識を検証するように設計された世界的に認められた認定プログラムです。この認定試験は、世界中の情報セキュリティ認証とトレーニングプログラムの大手プロバイダーである国際電子商業コンサルタント評議会(ECカウンシル)によって提供されています。
EC-Council Certified CISO(CCISO)認定試験は、情報セキュリティの専門家が潜在的な雇用主に知識、スキル、専門知識を実証する優れた方法です。この認定は業界で高く評価されており、情報セキュリティでのキャリアを強化したい人にとって貴重な資産と見なされています。
質問 # 29
The risk found after a control has been fully implemented is called:
- A. Residual Risk
- B. Transferred risk
- C. Post implementation risk
- D. Total Risk
正解:A
質問 # 30
What is the BEST reason for having a formal request for proposal process?
- A. Allows small companies to compete with larger companies
- B. Clearly identifies risks and benefits before funding is spent
- C. Informs suppliers a company is going to make a purchase
- D. Creates a timeline for purchasing and budgeting
正解:B
質問 # 31
The patching and monitoring of systems on a consistent schedule is required by?
- A. Local privacy laws
- B. Audit best practices
- C. Industry best practices
- D. Risk Management framework
正解:D
解説:
Explanation
質問 # 32
Which of the following provides an audit framework?
- A. Control Objectives for IT (COBIT)
- B. National Institute of Standards and Technology (NIST) SP 800-30
- C. International Organization Standard (ISO) 27002
- D. Payment Card Industry-Data Security Standard (PCI-DSS)
正解:A
質問 # 33
Scenario: Your organization employs single sign-on (user name and password only) as a convenience to your employees to access organizational systems and dat a. Permission to individual systems and databases is vetted and approved through supervisors and data owners to ensure that only approved personnel can use particular applications or retrieve information. All employees have access to their own human resource information, including the ability to change their bank routing and account information and other personal details through the Employee Self-Service application. All employees have access to the organizational VPN.
Recently, members of your organization have been targeted through a number of sophisticated phishing attempts and have compromised their system credentials. What action can you take to prevent the misuse of compromised credentials to change bank account information from outside your organization while still allowing employees to manage their bank information?
- A. Turn off VPN access for users originating from outside the country
- B. Block access to the Employee-Self Service application via VPN
- C. Force a change of all passwords
- D. Enable monitoring on the VPN for suspicious activity
正解:B
質問 # 34
The primary responsibility for assigning entitlements to a network share lies with which role?
- A. CISO
- B. Security system administrator
- C. Data owner
- D. Chief Information Officer (CIO)
正解:C
解説:
* Role of Data Owner:
* The data owner is responsible for defining and assigning entitlements to access network shares or other data repositories.
* They establish permissions based on business needs and sensitivity of the data.
* Why Not Other Options:
* A: The CISO sets security policies but does not manage specific entitlements.
* C: The CIO oversees IT strategy but typically delegates entitlement assignments to data owners.
* D: Security system administrators implement permissions but do not define them.
Reference:
Infosec Institute on Data Ownership and Entitlement Assignment
Reference: https://resources.infosecinstitute.com/certification/data-and-system-ownership/
質問 # 35
A recent audit has identified a few control exceptions and is recommending the implementation of technology and processes to address the finding. Which of the following is the MOST likely reason for the organization to reject the implementation of the recommended technology and processes?
- A. The organization has purchased cyber insurance
- B. The CIO of the organization disagrees with the finding
- C. The auditors have not followed proper auditing processes
- D. The risk tolerance of the organization permits this risk
正解:D
質問 # 36
During the 3rd quarter of a budget cycle, the CISO noticed she spent more than was originally planned in her annual budget. What is the condition of her current budgetary posture?
- A. The budget is operating at a deficit
- B. She has a surplus of operational expenses (OPEX)
- C. She can realign the budget through moderate capital expense (CAPEX) allocation
- D. The budget is in a temporary state of imbalance
正解:D
質問 # 37
Which of the following most commonly falls within the scope of an information security
governance steering committee?
- A. Interviewing candidates for information security specialist positions
- B. Developing content for security awareness programs
- C. Approving access to critical financial systems
- D. Vetting information security policies
正解:D
質問 # 38
An international organization is planning a project to implement encryption technologies to protect company confidential information. This organization has data centers on three continents. Which of the following would be considered a MAJOR constraint for the project?
- A. Encryption import/export regulations
- B. Time zone differences
- C. Compliance to local hiring laws
- D. Local customer privacy laws
正解:A
質問 # 39
Which of the following functions implements and oversees the use of controls to reduce risk when creating an information security program?
- A. Risk Assessment
- B. Risk Management
- C. Incident Response
- D. Network Security administration
正解:B
質問 # 40
Which of the following is a MAJOR consideration when an organization retains sensitive customer data and uses this data to better target the organization's products and services?
- A. Local privacy laws
- B. Financial reporting regulations
- C. Credit card compliance and regulations
- D. Strong authentication technologies
正解:A
質問 # 41
Scenario: The new CISO was informed of all the Information Security projects that the section has in progress. Two projects are over a year behind schedule and way over budget.
Using the best business practices for project management, you determine that the project correctly aligns with the organization goals. What should be verified next?
- A. Resources
- B. Budget
- C. Scope
- D. Constraints
正解:C
質問 # 42
What is an approach to estimating the strengths and weaknesses of alternatives used to determine options, which provide the BEST approach to achieving benefits while preserving savings called?
- A. Economic Impact analysis
- B. Cost-benefit analysis
- C. Business Impact Analysis
- D. Return on Investment
正解:B
解説:
Cost-benefit analysis (CBA) is a method used to evaluate the strengths and weaknesses of alternatives to determine the most cost-effective way to achieve benefits while preserving savings. This involves comparing the expected costs and benefits of a decision, ensuring optimal allocation of resources. It is more specific to decision-making than Business Impact Analysis (A), Economic Impact Analysis (B), or Return on Investment (C), which focus on other financial or strategic aspects.
Reference: https://artsandculture.google.com/entity/cost%E2%80%93benefit-analysis/m020w0x?hl=en
質問 # 43
Acceptable levels of information security risk tolerance in an organization should be determined by?
- A. CEO and board of director
- B. Corporate compliance committee
- C. CISO with reference to the company goals
- D. Corporate legal counsel
正解:A
質問 # 44
Scenario: Your organization employs single sign-on (user name and password only) as a convenience to your employees to access organizational systems and data. Permission to individual systems and databases is vetted and approved through supervisors and data owners to ensure that only approved personnel can use particular applications or retrieve information.
All employees have access to their own human resource information, including the ability to change their bank routing and account information and other personal details through the Employee Self-Service application. All employees have access to the organizational VPN. The organization wants a more permanent solution to the threat to user credential compromise through phishing.
What technical solution would BEST address this issue?
- A. Forcing password changes every 90 days
- B. Decreasing the number of employees with administrator privileges
- C. Multi-factor authentication employing hard tokens
- D. Professional user education on phishing conducted by a reputable vendor
正解:C
質問 # 45
What is a key policy that should be part of the information security plan?
- A. Training policy
- B. Remote Access policy
- C. Acceptable Use policy
- D. Account management policy
正解:C
解説:
An Acceptable Use Policy (AUP) is a critical component of an information security plan, as it defines acceptable and unacceptable actions for system and resource usage. It ensures users understand their responsibilities, reducing risks from misuse or negligence. While account management (A), training (B), and remote access (D) policies are important, the AUP provides the broad foundational guidance for user behavior.
Reference: https://www.exabeam.com/information-security/information-security-policy/
質問 # 46
As the Chief Information Security Officer, you want to ensure data shared securely, especially when shared with third parties outside the organization. What protocol provides the ability to extend the network perimeter with the use of encapsulation and encryption?
- A. Virtual Local Area Network (VLAN)
- B. File Transfer Protocol (FTP)
- C. Simple Mail Transfer Protocol
- D. Virtual Private Network (VPN)
正解:D
質問 # 47
An organization has decided to develop an in-house BCM capability. The organization has determined it is best to follow a BCM standard published by the International Organization for Standardization (ISO).
The BEST ISO standard to follow that outlines the complete lifecycle of BCM is?
- A. ISO 22318 Supply Chain Continuity
- B. ISO 22317 BIA
- C. ISO 22301 BCM Requirements
- D. ISO 27031 BCM Readiness
正解:C
解説:
ISO 22301 provides a comprehensive standard for Business Continuity Management (BCM) requirements, covering the complete BCM lifecycle, including planning, implementing, operating, monitoring, and improving BCM systems. While ISO 22318 (A) focuses on supply chain continuity and ISO 27031 (B) addresses ICT readiness, ISO 22301 offers a broader approach. ISO 22317 (D) pertains specifically to Business Impact Analysis (BIA).
Reference: https://www.smartsheet.com/content/iso-22301-business-continuity-guide
質問 # 48
Which of the following terms is used to describe countermeasures implemented to minimize risks to physical property, information, and computing systems?
- A. Security controls
- B. Security policies
- C. Security awareness
- D. Security frameworks
正解:A
解説:
* Definition of Security Controls:
* Security controls are countermeasures or safeguards implemented to minimize risks to physical property, information, and computing systems.
* They are categorized as physical, technical, or administrative controls.
* Purpose and Functionality:
* Ensure the confidentiality, integrity, and availability of systems and data.
* Examples include access controls, firewalls, encryption, and security training.
* Why Not Other Options:
* Security frameworks: Provide high-level guidelines for structuring security programs.
* Security policies: Define organizational rules and expectations but are not actionable countermeasures.
* Security awareness: Focuses on educating individuals, not implementing direct countermeasures.
Reference:
IBM Security Controls Overview
EC-Council CISO Module: Risk Management and Security Countermeasures.
Reference: https://www.ibm.com/cloud/learn/security-controls
質問 # 49
An organization is required to implement background checks on all employees with access to databases containing credit card information. This is considered a security
- A. Technical control
- B. Management control
- C. Administrative control
- D. Procedural control
正解:B
質問 # 50
Which of the following defines the boundaries and scope of a risk assessment?
- A. The assessment context
- B. The risk assessment charter
- C. The risk assessment framework
- D. The risk assessment schedule
正解:A
解説:
* Assessment Context Definition:
* The assessment context defines the boundaries and scope of a risk assessment by identifying what will be included or excluded, such as assets, processes, or business units.
* Components of Context:
* Clearly specifies geographical, organizational, and operational scope.
* Determines external and internal factors influencing the risk assessment.
* Importance:
* Provides clarity on what needs to be assessed and ensures stakeholders align their expectations.
References:
* EC-Council CISO Handbook on Risk Management Frameworks.
* CFocus Software Guidance on Risk Assessment Boundaries.
Reference: https://cfocussoftware.com/risk-management-framework/know-your-boundary/
質問 # 51
Involvement of senior management is MOST important in the development of:
- A. Standards and guidelines
- B. IT security procedures
- C. IT security implementation plans
- D. IT security policies
正解:D
質問 # 52
......
712-50試験問題と解答:https://www.jpntest.com/shiken/712-50-mondaishu
712-50実際の問題解答PDFは100%カバー率でリアル試験問題:https://drive.google.com/open?id=1ZBaRs7Vi4KeRL7KUVHGen39CyyIa9u2d