
PassTest 512-50リアル試験問題512-50練習問題集
厳密検証された512-50試験問題集と解答で無料提供の512-50問題と正解付き
質問 56
Scenario: Your program is developed around minimizing risk to information by focusing on people, technology, and operations.
An effective way to evaluate the effectiveness of an information security awareness program for end users, especially senior executives, is to conduct periodic:
- A. Scanning for viruses
- B. Controlled spear phishing campaigns
- C. Baselining of computer systems
- D. Password changes
正解: B
質問 57
A customer of a bank has placed a dispute on a payment for a credit card account. The banking system uses digital signatures to safeguard the integrity of their transactions. The bank claims that the system shows proof that the customer in fact made the payment. What is this system capability commonly known as?
- A. digital rights management
- B. strong authentication
- C. non-repudiation
- D. conflict resolution
正解: C
質問 58
During the 3rd quarter of a budget cycle, the CISO noticed she spent more than was originally planned in her annual budget. What is the condition of her current budgetary posture?
- A. She can realign the budget through moderate capital expense (CAPEX) allocation
- B. The budget is in a temporary state of imbalance
- C. She has a surplus of operational expenses (OPEX)
- D. The budget is operating at a deficit
正解: B
質問 59
When selecting a security solution with reoccurring maintenance costs after the first year (choose the BEST answer):
- A. Communicate future operating costs to the CIO/CFO and seek commitment from them to ensure the new solution's continued use
- B. Implement the solution and ask for the increased operating cost budget when it is time
- C. Defer selection until the market improves and cash flow is positive
- D. The CISO should cut other essential programs to ensure the new solution's continued use
正解: A
質問 60
An organization has a stated requirement to block certain traffic on networks. The implementation of controls will disrupt a manufacturing process and cause unacceptable delays, resulting in sever revenue disruptions.
Which of the following is MOST likely to be responsible for accepting the risk until mitigating controls can be implemented?
- A. The CFO
- B. The CISO
- C. Audit and Compliance
- D. The business owner
正解: D
質問 61
Scenario: The new CISO was informed of all the Information Security projects that the section has in progress.
Two projects are over a year behind schedule and way over budget.
Using the best business practices for project management, you determine that the project correctly aligns with the organization goals. What should be verified next?
- A. Constraints
- B. Resources
- C. Scope
- D. Budget
正解: C
質問 62
Acceptable levels of information security risk tolerance in an organization should be determined by?
- A. Corporate compliance committee
- B. CEO and board of director
- C. CISO with reference to the company goals
- D. Corporate legal counsel
正解: B
質問 63
Which of the following best describes the sensors designed to project and detect a light beam across an area?
- A. Thermal
- B. Air-aspirating
- C. Photo electric
- D. Smoke
正解: C
解説:
Reference: https://en.wikipedia.org/wiki/Photoelectric_sensor
質問 64
What is the SECOND step to creating a risk management methodology according to the National Institute of Standards and Technology (NIST) SP 800-30 standard?
- A. Evaluate risk avoidance criteria
- B. Mitigate risk
- C. Perform a risk assessment
- D. Determine appetite
正解: B
質問 65
When would it be more desirable to develop a set of decentralized security policies and procedures within an enterprise environment?
- A. When the enterprise is made up of many business units with diverse business activities, risks profiles and regulatory requirements.
- B. When there is a variety of technologies deployed in the infrastructure.
- C. When there is a need to develop a more unified incident response capability.
- D. When it results in an overall lower cost of operating the security program.
正解: A
質問 66
From an information security perspective, information that no longer supports the main purpose of the business should be:
- A. analyzed under the retention policy
- B. protected under the information classification policy.
- C. analyzed under the data ownership policy.
- D. assessed by a business impact analysis.
正解: A
質問 67
A recommended method to document the respective roles of groups and individuals for a given process is to:
- A. Develop a Responsible, Accountable, Consulted, Informed (RACI) chart
- B. Develop an isolinear response matrix with cost benefit analysis projections
- C. Develop a telephone call tree for emergency response
- D. Develop a detailed internal organization chart
正解: A
質問 68
Which of the following will be MOST helpful for getting an Information Security project that is behind schedule back on schedule?
- A. Involve internal audit
- B. Upper management support
- C. More frequent project milestone meetings
- D. More training of staff members
正解: B
質問 69
Access Control lists (ACLs), Firewalls, and Intrusion Prevention Systems are examples of
- A. Software segmentation controls
- B. Network based security detective controls
- C. User segmentation controls
- D. Network based security preventative controls
正解: D
質問 70
When deploying an Intrusion Prevention System (IPS) the BEST way to get maximum protection from the system is to deploy it
- A. In promiscuous mode and only detect malicious traffic.
- B. In-line and turn on blocking mode to stop malicious traffic.
- C. In promiscuous mode and block malicious traffic.
- D. In-line and turn on alert mode to stop malicious traffic.
正解: B
質問 71
The Security Operations Center (SOC) just purchased a new intrusion prevention system (IPS) that needs to be deployed in-line for best defense. The IT group is concerned about putting the new IPS in-line because it might negatively impact network availability. What would be the BEST approach for the CISO to reassure the IT group?
- A. Work with the IT group and tell them to put IPS in-line and say it won't cause any network impact
- B. Explain to the IT group that the IPS won't cause any network impact because it will fail open
- C. Explain to the IT group that the IPS will fail open once in-line however it will be deployed in monitor mode for a set period of time to ensure that it doesn't block any legitimate traffic
- D. Explain to the IT group that this is a business need and the IPS will fail open however, if there is a network failure the CISO will accept responsibility
正解: C
質問 72
The mean time to patch, number of virus outbreaks prevented, and number of vulnerabilities mitigated are examples of what type of performance metrics?
- A. Compliance metrics
- B. Risk metrics
- C. Management metrics
- D. Operational metrics
正解: D
質問 73
Who is responsible for verifying that audit directives are implemented?
- A. IT Security
- B. Internal Audit
- C. IT Management
- D. BOD Audit Committee
正解: B
解説:
Reference: https://www.eccouncil.org/information-security-management/
質問 74
Which of the following functions evaluates risk present in IT initiatives and/or systems when implementing an information security program?
- A. Risk Management
- B. Risk Assessment
- C. Vulnerability Assessment
- D. System Testing
正解: B
質問 75
The CIO of an organization has decided to assign the responsibility of internal IT audit to the IT team. This is consider a bad practice MAINLY because
- A. This represents a bad implementation of the Least Privilege principle
- B. The IT team is not familiar in IT audit practices
- C. This represents a conflict of interest
- D. The IT team is not certified to perform audits
正解: C
質問 76
The process for management approval of the security certification process which states the risks and mitigation of such risks of a given IT system is called
- A. Security system analysis
- B. Security accreditation
- C. Security certification
- D. Alignment with business practices and goals.
正解: B
質問 77
As a CISO you need to understand the steps that are used to perform an attack against a network. Put each step into the correct order.
1.Covering tracks
2.Scanning and enumeration
3.Maintaining Access
4.Reconnaissance
5.Gaining Access
- A. 4, 2, 5, 3, 1
- B. 2, 5, 3, 1, 4
- C. 4, 3, 5, 2, 1
- D. 4, 5, 2, 3, 1
正解: A
質問 78
Which of the following is the MOST effective method for discovering common technical vulnerabilities within the IT environment?
- A. Performing system scans
- B. Reviewing system administrator logs
- C. Auditing configuration templates
- D. Checking vendor product releases
正解: A
質問 79
When project costs continually increase throughout implementation due to large or rapid changes in customer or user requirements, this is commonly known as:
- A. Expectations management
- B. Prototype issues
- C. Cost/benefit adjustments
- D. Scope creep
正解: D
解説:
Reference:
http://www.umsl.edu/~sauterv/analysis/6840_f03_papers/gurlen/
質問 80
While designing a secondary data center for your company what document needs to be analyzed to determine to how much should be spent on building the data center?
- A. Business continuity plan
- B. Application mapping document
- C. Disaster recovery strategic plan
- D. Enterprise Risk Assessment
正解: C
質問 81
......
無料でゲット!高評価EC-COUNCIL 512-50試験問題集を今すぐダウンロード!:https://www.passtest.jp/EC-COUNCIL/512-50-shiken.html