最新的EC-COUNCIL EC-Council Information Security Manager (E|ISM) - 512-50免費考試真題
Who is responsible for securing networks during a security incident?
正確答案: D
What is meant by password aging?
正確答案: A
說明:(僅 Fast2test 成員可見)
Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined security policy and framework for their Information Security Program. Your new boss, the Chief Financial Officer, has asked you to draft an outline of a security policy and recommend an industry/sector neutral information security control framework for implementation.
Your Corporate Information Security Policy should include which of the following?
Your Corporate Information Security Policy should include which of the following?
正確答案: A
The amount of risk an organization is willing to accept in pursuit of its mission is known as
正確答案: C
Which of the following is considered one of the most frequent failures in project management?
正確答案: C
When dealing with risk, the information security practitioner may choose to:
正確答案: C
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used as audit baselines. The audit report was presented to the CISO and a variety of high, medium and low rated gaps were identified.
The CISO has implemented remediation activities. Which of the following is the MOST logical next step?
The CISO has implemented remediation activities. Which of the following is the MOST logical next step?
正確答案: D
說明:(僅 Fast2test 成員可見)
Which of the following is MOST likely to be discretionary?
正確答案: B
A person in your security team calls you at night and informs you that one of your web applications is potentially under attack from a cross-site scripting vulnerability. What do you do?
正確答案: D
Providing oversight of a comprehensive information security program for the entire organization is the primary responsibility of which group under the InfoSec governance framework?
正確答案: D
What is the BEST reason for having a formal request for proposal process?
正確答案: C
An organization licenses and uses personal information for business operations, and a server containing that information has been compromised. What kind of law would require notifying the owner or licensee of this incident?
正確答案: C
You currently cannot provide for 24/7 coverage of your security monitoring and incident response duties and your company is resistant to the idea of adding more full-time employees to the payroll. Which combination of solutions would help to provide the coverage needed without the addition of more dedicated staff? (choose the best answer):
正確答案: D
Creating a secondary authentication process for network access would be an example of?
正確答案: A