2021年最新のに更新された検証済みの合格させる712-50リアル試験問題と解答 [Q169-Q185]

Share

2021年最新のに更新された検証済みの合格させる712-50リアル試験問題と解答

問題集返金保証付きの712-50問題集公式問題集

質問 169
A global health insurance company is concerned about protecting confidential information. Which of the following is of MOST concern to this organization?

  • A. Compliance to the Payment Card Industry (PCI) regulations.
  • B. Alignment with financial reporting regulations for each country where they operate.
  • C. Alignment with International Organization for Standardization (ISO) standards.
  • D. Compliance with patient data protection regulations for each country where they operate.

正解: D

 

質問 170
You have a system with 2 identified risks. You determine the probability of one risk occurring is higher than the

  • A. Risk impact comparison
  • B. Relative likelihood of event
  • C. Comparative threat analysis
  • D. Controlled mitigation effort

正解: B

 

質問 171
The process for identifying, collecting, and producing digital information in support of legal proceedings is called

  • A. electronic review.
  • B. evidence tampering.
  • C. chain of custody.
  • D. electronic discovery.

正解: D

 

質問 172
Access Control lists (ACLs), Firewalls, and Intrusion Prevention Systems are examples of________________.

  • A. Network based security preventative controls
  • B. Network based security detective controls
  • C. User segmentation controls
  • D. Software segmentation controls

正解: A

 

質問 173
What is the primary reason for performing vendor management?

  • A. To document the relationship between the company and vendor
  • B. To establish a vendor selection process
  • C. To understand the risk coverage that are being mitigated by the vendor
  • D. To define the partnership for long-term success

正解: C

 

質問 174
Scenario: Your program is developed around minimizing risk to information by focusing on people, technology, and operations.
You have decided to deal with risk to information from people first. How can you minimize risk to your most sensitive information before granting access?

  • A. Develop an Information Security Awareness program
  • B. Set your firewall permissions aggressively and monitor logs regularly.
  • C. Monitor employee browsing and surfing habits
  • D. Conduct background checks on individuals before hiring them

正解: D

 

質問 175
The process for identifying, collecting, and producing digital information in support of legal proceedings is called _____________________________.

  • A. electronic review
  • B. chain of custody
  • C. evidence tampering
  • D. electronic discovery

正解: D

 

質問 176
At which point should the identity access management team be notified of the termination of an employee?

  • A. At the end of the day once the employee is off site
  • B. During the monthly review cycle
  • C. Before an audit
  • D. Immediately so the employee account(s) can be disabled

正解: D

 

質問 177
Which of the following best describes the sensors designed to project and detect a light beam across an area?

  • A. Thermal
  • B. Air-aspirating
  • C. Photo electric
  • D. Smoke

正解: C

 

質問 178
The executive board has requested that the CISO of an organization define and Key Performance Indicators (KPI) to measure the effectiveness of the security awareness program provided to call center employees. Which of the following can be used as a KPI?

  • A. Number of successful social engineering attempts on the call center
  • B. Number of callers who report security issues.
  • C. Number of callers who abandon the call before speaking with a representative
  • D. Number of callers who report a lack of customer service from the call center

正解: A

 

質問 179
A Chief Information Security Officer received a list of high, medium, and low impact audit findings.
Which of the following represents the BEST course of action?

  • A. if the findings impact regulatory compliance, remediate the high findings as quickly as possible.
  • B. If the findings do not impact regulatory compliance, remediate only the high and medium risk findings.
  • C. If the findings impact regulatory compliance, try to apply remediation that will address the most findings for the least cost.
  • D. If the findings do not impact regulatory compliance, review current security controls.

正解: A

 

質問 180
Information Security is often considered an excessive, after-the-fact cost when a project or initiative is completed. What can be done to ensure that security is addressed cost effectively?

  • A. Integrate security requirements into project inception
  • B. User awareness training for all employees
  • C. Installation of new firewalls and intrusion detection systems
  • D. Launch an internal awareness campaign

正解: A

 

質問 181
To have accurate and effective information security policies how often should the CISO review the organization policies?

  • A. Quarterly
  • B. Every 6 months
  • C. At least once a year
  • D. Before an audit

正解: C

 

質問 182
Risk that remains after risk mitigation is known as

  • A. Residual risk
  • B. Persistent risk
  • C. Accepted risk
  • D. Non-tolerated risk

正解: A

 

質問 183
Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small retail merchant but it is expected to grow to a global customer base of many millions of customers in just a few years.
This global retail company is expected to accept credit card payments. Which of the following is of MOST concern when defining a security program for this organization?

  • A. International encryption restrictions
  • B. Adherence to local data breach notification laws
  • C. Compliance with local government privacy laws
  • D. Compliance to Payment Card Industry (PCI) data security standards

正解: D

 

質問 184
A recent audit has identified a few control exceptions and is recommending the implementation of technology and processes to address the finding.
Which of the following is the MOST likely reason for the organization to reject the implementation of the recommended technology and processes?

  • A. The risk tolerance of the organization permits this risk
  • B. The CIO of the organization disagrees with the finding
  • C. The auditors have not followed proper auditing processes
  • D. The organization has purchased cyber insurance

正解: A

 

質問 185
......

更新されたPDF(2021年最新)実際にあるEC-COUNCIL 712-50試験問題:https://www.passtest.jp/EC-COUNCIL/712-50-shiken.html

検証済みの712-50試験問題集PDF[2021年最新] 成功の秘訣はPassTest:https://drive.google.com/open?id=1Mo1Of7EQ5Q4u2HoW_z9gQnZHOsQhzoSX