合格目指せ712-50試験最新の712-50試験問題集PDF 2025年更新 [Q237-Q254]

Share

合格目指せ712-50試験最新の712-50試験問題集PDF 2025年更新

712-50試験問題集、365日更新無料サンプル

質問 # 237
Credit card information, medical data, and government records are all examples of:

  • A. Confidential/Protected Information
  • B. Bodily Information
  • C. Territorial Information
  • D. Communications Information
  • E. None

正解:A


質問 # 238
When a critical vulnerability has been discovered on production systems and needs to be fixed immediately, what is the BEST approach for a CISO to mitigate the vulnerability under tight budget constraints?

  • A. Deploy countermeasures and compensating controls until the budget is available
  • B. Transfer financial resources from other critical programs
  • C. Take the system off line until the budget is available
  • D. Schedule an emergency meeting and request the funding to fix the issue

正解:A


質問 # 239
Which of the following is a benefit of information security governance?

  • A. Questioning the trust in vendor relationships
  • B. Direct involvement of senior management in developing control processes
  • C. Increasing the risk of decisions based on incomplete management information
  • D. Reduction of the potential for civil and legal liability

正解:D


質問 # 240
Which of the following is the MAIN reason to follow a formal risk management process in an organization that hosts and uses privately identifiable information (PII) as part of their business models and processes?

  • A. Need to better understand the risk associated with using PII data
  • B. Need to comply with breach disclosure laws
  • C. Fiduciary responsibility to safeguard credit information
  • D. Need to transfer the risk associated with hosting PII data

正解:A


質問 # 241
Scenario: The new CISO was informed of all the Information Security projects that the section has in progress. Two projects are over a year behind schedule and way over budget.
Which of the following will be most helpful for getting an Information Security project that is behind schedule back on schedule?

  • A. Involve internal audit
  • B. More training of staff members
  • C. Upper management support
  • D. More frequent project milestone meetings

正解:C


質問 # 242
Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small retail merchant but it is expected to grow to a global customer base of many millions of customers in just a few years.
Which of the following would be the FIRST step when addressing Information Security formally and consistently in this organization?

  • A. Contract a third party to perform a security risk assessment
  • B. Define formal roles and responsibilities for Information Security
  • C. create an executive security steering committee
  • D. Define formal roles and responsibilities for Internal audit functions

正解:B


質問 # 243
A Chief Information Security Officer received a list of high, medium, and low impact audit findings.
Which of the following represents the BEST course of action?

  • A. If the findings do not impact regulatory compliance, remediate only the high and medium risk findings.
  • B. If the findings do not impact regulatory compliance, review current security controls.
  • C. if the findings impact regulatory compliance, remediate the high findings as quickly as possible.
  • D. If the findings impact regulatory compliance, try to apply remediation that will address the most findings for the least cost.

正解:C

解説:
Explanation/Reference:


質問 # 244
From an information security perspective, information that no longer supports the main purpose of the business should be:

  • A. analyzed under the retention policy.
  • B. analyzed under the data ownership policy
  • C. assessed by a business impact analysis.
  • D. protected under the information classification policy

正解:A

解説:
Explanation


質問 # 245
SCENARIO: Critical servers show signs of erratic behavior within your organization's intranet. Initial information indicates the systems are under attack from an outside entity. As the Chief Information Security Officer (CISO), you decide to deploy the Incident Response Team (IRT) to determine the details of this incident and take action according to the information available to the team.
During initial investigation, the team suspects criminal activity but cannot initially prove or disprove illegal actions. What is the MOST critical aspect of the team's activities?

  • A. Preservation of information
  • B. Determination of the attack source
  • C. Eradication of malware and system restoration
  • D. Regular communication of incident status to executives

正解:A


質問 # 246
The success of the Chief Information Security Officer is MOST dependent upon:

  • A. development of relationships with organization executives
  • B. following the recommendations of consultants and contractors
  • C. favorable audit findings
  • D. raising awareness of security issues with end users

正解:A


質問 # 247
What oversight should the information security team have in the change management process for application security?

  • A. Information security should be aware of all application changes and work with developers before changes and deployed in production
  • B. Information security should be aware of any significant application security changes and work with developer to test for vulnerabilities before changes are deployed in production
  • C. Information security should be informed of changes to applications only
  • D. Development team should tell the information security team about any application security flaws

正解:B


質問 # 248
Annual Loss Expectancy is derived from the function of which two factors?

  • A. Annual Rate of Occurrence and Asset Value
  • B. Annual Rate of Occurrence and Single Loss Expectancy
  • C. Single Loss Expectancy and Exposure Factor
  • D. Safeguard Value and Annual Rate of Occurrence

正解:B

解説:
Definition of Annual Loss Expectancy (ALE)
* ALE is a quantitative risk analysis metric used to estimate the annual financial impact of a risk.
* Formula: ALE = Annual Rate of Occurrence (ARO) × Single Loss Expectancy (SLE) Key Components
* Annual Rate of Occurrence (ARO): The estimated frequency of a specific risk occurring in a year.
* Single Loss Expectancy (SLE): The financial impact of a single occurrence of the risk, calculated as Asset Value × Exposure Factor.
Comparison of Options
* A. Annual Rate of Occurrence and Asset Value: Asset Value is used indirectly in SLE but not directly with ARO.
* B. Single Loss Expectancy and Exposure Factor: These factors combine to calculate SLE, not ALE.
* C. Safeguard Value and Annual Rate of Occurrence: Safeguard Value is unrelated to ALE calculation.
EC-Council References
* EC-Council frameworks and CISO resources consistently highlight ALE as a critical tool for financial risk assessment.


質問 # 249
The total cost of security controls should:

  • A. Should not matter, as long as the information resource is protected
  • B. Be less than the value of the information resource being protected
  • C. Be equal to the value of the information resource being protected
  • D. Be greater than the value of the information resource being protected

正解:B

解説:
The total cost of security controls must always be less than the value of the protected asset, ensuring cost- effectiveness in resource allocation.
* Economic Principle of Security:
* Spending more to protect an asset than its value undermines the financial justification for security.
* Cost-Benefit Consideration:
* Security investments should provide value greater than their cost by reducing potential losses and improving operational resilience.
* Relevance of Other Options:
* Equal to Value: Break-even point but not cost-efficient.
* Greater than Value: Leads to inefficiencies.
* Should Not Matter: Contradicts sound financial practices.
* Economic Feasibility of Security Measures: Discusses balancing security costs with asset value.
* Risk-Driven Decision Making: Guides the alignment of resource allocation with organizational goals and asset value.
EC-Council CISO References:


質問 # 250
Which business stakeholder is accountable for the integrity of a new information system?

  • A. CISO
  • B. Board of directors
  • C. Compliance Officer
  • D. Project manager

正解:A

解説:
Explanation


質問 # 251
Which of the following is used to lure attackers into false environments so they can be monitored, contained, or blocked from reaching critical systems?

  • A. Deception technology.
  • B. Vulnerability management.
  • C. Shadow applications.
  • D. Segmentation controls.

正解:C


質問 # 252
An access point (AP) is discovered using Wireless Equivalent Protocol (WEP). The ciphertext sent by the AP is encrypted with the same key and cipher used by its stations. What authentication method is being used?

  • A. Open
  • B. Asynchronous
  • C. Shared key
  • D. None

正解:C


質問 # 253
A CISO decides to analyze the IT infrastructure to ensure security solutions adhere to the concepts of how hardware and software is implemented and managed within the organization. Which of the following principles does this best demonstrate?

  • A. Proper budget management
  • B. Leveraging existing implementations
  • C. Alignment with the business
  • D. Effective use of existing technologies

正解:D

解説:
* By analyzing the IT infrastructure and ensuring security solutions adhere to the principles of how hardware and software are implemented and managed, the CISO demonstrates effective use of existing technologies.
* This principle focuses on leveraging and optimizing current IT assets to maximize value and efficiency.
Why Other Options Are Less Relevant:
* A. Alignment with the business: This relates to ensuring security goals align with organizational objectives but is broader than analyzing infrastructure.
* C. Leveraging existing implementations: While related, this does not explicitly address management and implementation of hardware/software.
* D. Proper budget management: Budget management focuses on financial aspects, not technical alignment.
EC-Council CISO Reference:Emphasizes the importance of maximizing existing technology investments as part of an efficient and secure IT strategy.


質問 # 254
......

712-50問題集、あなたを合格させる認証試験:https://www.passtest.jp/EC-COUNCIL/712-50-shiken.html

まもなくセール終了!リアル712-50のPDF解答を使おう:https://drive.google.com/open?id=1bbxF8BF6ZjxuBYhlcTUWJRV29Nn5QE3s