Pass Your EISM 512-50 Exam on May 08, 2022 with 402 Questions [Q52-Q73]

Rate this post

Pass Your EISM 512-50 Exam on May 08, 2022 with 402 Questions

512-50 Free Exam Study Guide! (Updated 402 Questions)

For more info visit:

EC-Council 512-50 Exam Reference

What is the duration of the 512-50 Exam

  • Length of Examination: 120 minutes
  • Number of Questions: 150
  • Passing Score 70%
  • Format: Multiple choices, multiple answers

 

NO.52 Your company has limited resources to spend on security initiatives. The Chief Financial Officer asks you to prioritize the protection of information resources based on their value to the company. It is essential that you be able to communicate in language that your fellow executives will understand. You should:

 
 
 
 

NO.53 Which International Organization for Standardization (ISO) below BEST describes the performance of risk management, and includes a five-stage risk management methodology.

 
 
 
 

NO.54 The network administrator wants to strengthen physical security in the organization. Specifically, to implement a solution stopping people from entering certain restricted zones without proper credentials. Which of following physical security measures should the administrator use?

 
 
 
 

NO.55 An organization has a number of Local Area Networks (LANs) linked to form a single Wide Area Network (WAN). Which of the following would BEST ensure network continuity?

 
 
 
 

NO.56 When analyzing and forecasting a capital expense budget what are not included?

 
 
 
 

NO.57 Which of the following represents the BEST method for obtaining business unit acceptance of security controls within an organization?

 
 
 
 

NO.58 Scenario: As you begin to develop the program for your organization, you assess the corporate culture and determine that there is a pervasive opinion that the security program only slows things down and limits the performance of the “real workers.” What must you do first in order to shift the prevailing opinion and reshape corporate culture to understand the value of information security to the organization?

 
 
 
 

NO.59 Which of the following activities is the MAIN purpose of the risk assessment process?

 
 
 
 

NO.60 The Security Operations Center (SOC) just purchased a new intrusion prevention system (IPS) that needs to be deployed in-line for best defense. The IT group is concerned about putting the new IPS in-line because it might negatively impact network availability. What would be the BEST approach for the CISO to reassure the IT group?

 
 
 
 

NO.61 A CISO sees abnormally high volumes of exceptions to security requirements and constant pressure from business units to change security processes. Which of the following represents the MOST LIKELY cause of this situation?

 
 
 
 

NO.62 What is one key difference between Capital expenditures and Operating expenditures?

 
 
 
 

NO.63 The organization does not have the time to remediate the vulnerability; however it is critical to release the application. Which of the following needs to be further evaluated to help mitigate the risks?

 
 
 
 

NO.64 Which of the following most commonly falls within the scope of an information security governance steering committee?

 
 
 
 

NO.65 Scenario: Your corporate systems have been under constant probing and attack from foreign IP addresses for more than a week. Your security team and security infrastructure have performed well under the stress. You are confident that your defenses have held up under the test, but rumors are spreading that sensitive customer data has been stolen and is now being sold on the Internet by criminal elements. During your investigation of the rumored compromise you discover that data has been breached and you have discovered the repository of stolen data on a server located in a foreign country. Your team now has full access to the data on the foreign server.
What action should you take FIRST?

 
 
 
 

NO.66 Creating a secondary authentication process for network access would be an example of?

 
 
 
 

NO.67 The executive board has requested that the CISO of an organization define and Key Performance Indicators (KPI) to measure the effectiveness of the security awareness program provided to call center employees.
Which of the following can be used as a KPI?

 
 
 
 

NO.68 Smith, the project manager for a larger multi-location firm, is leading a software project team that has 18 members, 5 of which are assigned to testing. Due to recent recommendations by an organizational quality audit team, the project manager is convinced to add a quality professional to lead to test team at additional cost to the project.
The project manager is aware of the importance of communication for the success of the project and takes the step of introducing additional communication channels, making it more complex, in order to assure quality levels of the project. What will be the first project management document that Smith should change in order to accommodate additional communication channels?

 
 
 
 

NO.69 A global retail organization is looking to implement a consistent Disaster Recovery and Business Continuity Process across all of its business units. Which of the following standards and guidelines can BEST address this organization’s need?

 
 
 
 

NO.70 A Chief Information Security Officer received a list of high, medium, and low impact audit findings. Which of the following represents the BEST course of action?

 
 
 
 

NO.71 Scenario: Your organization employs single sign-on (user name and password only) as a convenience to your employees to access organizational systems and data. Permission to individual systems and databases is vetted and approved through supervisors and data owners to ensure that only approved personnel can use particular applications or retrieve information. All employees have access to their own human resource information, including the ability to change their bank routing and account information and other personal details through the Employee Self-Service application. All employees have access to the organizational VPN.
Recently, members of your organization have been targeted through a number of sophisticated phishing attempts and have compromised their system credentials. What action can you take to prevent the misuse of compromised credentials to change bank account information from outside your organization while still allowing employees to manage their bank information?

 
 
 
 

NO.72 Information Security is often considered an excessive, after-the-fact cost when a project or initiative is completed. What can be done to ensure that security is addressed cost effectively?

 
 
 
 

NO.73 What is the FIRST step in developing the vulnerability management program?

 
 
 
 

512-50 Dumps for EISM Certified Exam Questions and Answer: https://www.test4cram.com/512-50_real-exam-dumps.html

         

Related Links: www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw

Leave a Reply

Your email address will not be published. Required fields are marked *

Enter the text from the image below