EC-Council 712-50 Sample Questions:

01. Which of the following would not be considered an essential component of the strategic planning process?
a) Select the right people to be on the team
b) Acquire a planning tool
c) Select a model to follow
d) Set a schedule
02. An organization wants to purchase a turnkey inventory management system consisting of hardware and software. The organization wants to keep the price low, but its most important criteria are the experience and capabilities of the contractor.
Which procurement method is best for this situation?
a) Best value
b) Lowest price technically acceptable (LPTA)
c) Cost plus
d) Time and materials
03. A security analyst is reviewing the security logs of a web server for indicators of compromise. Which of the following control functionalities is this an example of?
a) Detective
b) Preventive
c) Recovery
d) Directive
04. The CISO is writing an organization security policy. This is an example of which of the following control types?
a) Administrative
b) Technical
c) Physical
d) Detective
05. An e-commerce site that accepts online payment is expanding and hires a CISO to ensure that the organization is complying with industry regulations and standards.
Which of the following fraameworks is of greatest concern to the CISO for ensuring compliance?
a) SOX
c) ISO/IEC 27001
06. Which of the following best describes the critical path in project management?
a) Activities that, if changed, will change the end date of the project
b) Activities that will change the end date of the project
c) Activities that are critical to the project
d) Activities that are not critical to the project
07. A disgruntled employee breaks into the organization and steals critical data after finding out he will be laid off due to downsizing. This is an example of what type of physical security threat?
a) Manmade threat
b) Natural threat
c) Environmental threat
d) Supply system threat
08. NIST SP 800-53 outlines management, operational, and technical classes. Which of the following NIST control families  is an example of a management control class?
a) Risk Assessment
b) Awareness and Training
c) Physical and Environmental Protection
d) Personnel Security
09. A publicly traded company collects cardholder data in the course of business operations. The organization’s CEO recognizes the importance of information security and hires a CISO. Which of the following must the CISO ensure the business is compliant 
c) PCI DSS and SOX
d) GDPR and SOX
10. Of the methods listed, what is the best countermeasure against social engineering attacks?
a) Training
b) Practice and drills
c) Observation
d) Reading


Question: 01
Answer: b
Question: 02
Answer: a
Question: 03
Answer: a
Question: 04
Answer: a
Question: 05
Answer: d
Question: 06
Answer: d
Question: 07
Answer: a
Question: 08
Answer: a
Question: 09
Answer: c
Question: 10
Answer: b

