Certification Practice Test | PDF Questions | Actual Questions | Test Engine | Pass4Sure
512-50 : Information Security Manager (E|ISM) Exam

EC-Council 512-50 Questions & Answers
Full Version: 100 Q&A
Latest 512-50 Practice Tests with Actual Questions
Get Complete pool of questions with Premium PDF and Test Engine
Exam Code : 512-50
Exam Name : Information Security Manager (E|ISM)
Vendor Name :
"EC-COUNCIL"
512-50 Dumps
512-50 Braindumps
512-50 Real Questions
512-50 Practice Test
512-50 Actual Questions
killexams.com EC-COUNCIL 512-50
Information Security Manager (E|ISM)
https://killexams.com/pass4sure/exam-detail/512-50
Question: 84
Which of the following is MOST important when dealing with an Information Security Steering committee:
Include a mix of members from different departments and staff levels.
Ensure that security policies and procedures have been vetted and approved.
Review all past audit and compliance reports.
Be briefed about new trends and products at each meeting by a vendor.
Answer: C
Question: 85
When briefing senior management on the creation of a governance process, the MOST important aspect should be:
information security metrics.
knowledge required to analyze each issue.
baseline against which metrics are evaluated.
linkage to business area objectives.
Answer: D
Question: 86
What is the BEST way to achieve on-going compliance monitoring in an organization?
Only check compliance right before the auditors are scheduled to arrive onsite.
Outsource compliance to a 3rd party vendor and let them manage the program.
Have Compliance and Information Security partner to correct issues as they arise.
Have Compliance direct Information Security to fix issues after the auditors report.
Answer: C
Question: 87
Which of the following is considered the MOST effective tool against social engineering?
Anti-phishing tools
Anti-malware tools
Effective Security Vulnerability Management Program
Effective Security awareness program
Answer: D
Question: 88 Risk is defined as:
Threat times vulnerability divided by control
Advisory plus capability plus vulnerability
Asset loss times likelihood of event
Quantitative plus qualitative impact
Answer: A
Question: 89
When would it be more desirable to develop a set of decentralized security policies and procedures within an enterprise environment?
When there is a need to develop a more unified incident response capability.
When the enterprise is made up of many business units with diverse business activities, risks profiles and regulatory requirements.
When there is a variety of technologies deployed in the infrastructure.
When it results in an overall lower cost of operating the security program.
Answer: B
Question: 90
The FIRST step in establishing a security governance program is to?
Conduct a risk assessment.
Obtain senior level sponsorship.
Conduct a workshop for all end users.
Prepare a security budget.
Answer: B
Question: 91
Risk that remains after risk mitigation is known as
Persistent risk
Residual risk
Accepted risk
Non-tolerated risk
Answer: B
Question: 92
In which of the following cases, would an organization be more prone to risk acceptance vs. risk mitigation?
The organization uses exclusively a quantitative process to measure risk
The organization uses exclusively a qualitative process to measure risk
The organizationâs risk tolerance is high
The organizationâs risk tolerance is lo
Answer: C
Question: 93
The PRIMARY objective for information security program development should be:
Reducing the impact of the risk to the business.
Establishing strategic alignment with business continuity requirements
Establishing incident response programs.
Identifying and implementing the best security solutions.
Answer: A
Question: 94
A business unit within your organization intends to deploy a new technology in a manner that places it in violation of existing information security standards.
What immediate action should the information security manager take?
Enforce the existing security standards and do not allow the deployment of the new technology.
Amend the standard to permit the deployment.
If the risks associated with that technology are not already identified, perform a risk analysis to quantify the risk, and allow the business unit to proceed based on the identified risk level.
Permit a 90-day window to see if an issue occurs and then amend the standard if there are no issues.
Answer: C
Question: 95
According to ISO 27001, of the steps for establishing an Information Security Governance program listed below, which comes first?
Identify threats, risks, impacts and vulnerabilities
Decide how to manage risk
Define the budget of the Information Security Management System
Define Information Security Policy
Answer: D
Question: 96
From an information security perspective, information that no longer supports the main purpose of the business should be:
assessed by a business impact analysis.
protected under the information classification policy.
analyzed under the data ownership policy.
analyzed under the retention policy
Answer: D
Question: 97
What is the main purpose of the Incident Response Team?
Ensure efficient recovery and reinstate repaired systems
Create effective policies detailing program activities
Communicate details of information security incidents
Provide current employee awareness programs
Answer: A
Question: 98
Information security policies should be reviewed:
by stakeholders at least annually
by the CISO when new systems are brought online
by the Incident Response team after an audit
by internal audit semiannually
Answer: A
Question: 99
An organization is looking for a framework to measure the efficiency and effectiveness of their Information Security Management System.
Which of the following international standards can BEST assist this organization?
International Organization for Standardizations C 27004 (ISO-27004)
Payment Card Industry Data Security Standards (PCI-DSS)
Control Objectives for Information Technology (COBIT)
International Organization for Standardizations C 27005 (ISO-27005)
Answer: A
Question: 100
Which of the following is the PRIMARY purpose of International Organization for Standardization (ISO) 27001?
Use within an organization to formulate security requirements and objectives
Implementation of business-enabling information security
Use within an organization to ensure compliance with laws and regulations
To enable organizations that adopt it to obtain certifications
Answer: B
User: Nicholi*****![]() ![]() ![]() ![]() ![]() Even after failing the exam on my first attempt, I continued practicing with killexams.com and a reliable study book. The second time, I passed with a strong score, thanks to the precision of the practice questions that closely matched the actual exam format. While some questions seemed overemphasized, I remained organized and completed the exam successfully. |
User: Sakoiya*****![]() ![]() ![]() ![]() ![]() I was impressed by killexams.com exceptional exam guide, and I owe them my gratitude for my incredible score on the 512-50 exam. Their questions and answers taught me the concepts well, and I answered 95% of the questions correctly. |
User: Zariyah*****![]() ![]() ![]() ![]() ![]() I am delighted to announce that I passed the 512-50 exam, and I owe thanks to the helpful team at Killexams.com for their support. Although the questions in the exam were not entirely covered by the questions and answers provided, I appreciate the effort made by Killexams.com to make us technically sound. It was a great program that helped me secure my position in the 512-50 exam. |
User: Pavlina*****![]() ![]() ![]() ![]() ![]() I thought passing the 512-50 exam was impossible due to my training schedule. But after referring to the exam material from Killexams.com, I was able to achieve a terrific score within less than 10 days of studying. Thanks to their guidance, I had hope and achieved my goal of becoming an IT certified professional. |
User: Aisyah*****![]() ![]() ![]() ![]() ![]() Thank you for the 512-50 practice tests. I was able to identify most of the questions and simulations that were already covered in your practice tests. I scored 97% marks in the exam. After reading several books, I was still confused about the right material to use for exam preparation. I was looking for an easy-to-understand guideline for the 512-50 exam with simple questions and answers, and Killexams.com Questions and Answers satisfied my need by defining the complicated subjects in the most effective manner. In the actual exam, I scored 97%, which exceeded my expectation. Thanks to Killexams.com for their awesome guideline. |
Features of iPass4sure 512-50 Exam
- Files: PDF / Test Engine
- Premium Access
- Online Test Engine
- Instant download Access
- Comprehensive Q&A
- Success Rate
- Real Questions
- Updated Regularly
- Portable Files
- Unlimited Download
- 100% Secured
- Confidentiality: 100%
- Success Guarantee: 100%
- Any Hidden Cost: $0.00
- Auto Recharge: No
- Updates Intimation: by Email
- Technical Support: Free
- PDF Compatibility: Windows, Android, iOS, Linux
- Test Engine Compatibility: Mac / Windows / Android / iOS / Linux
Premium PDF with 100 Q&A
Get Full VersionAll EC-Council Exams
EC-Council ExamsCertification and Entry Test Exams
Complete exam list