EC-Council 712-50 Sample Questions:

01. What is the BEST way to achieve on-going compliance monitoring in an organization?
a) Only check compliance right before the auditors are scheduled to arrive onsite.
b) Have Compliance and Information Security partner to correct issues as they arise.
c) Outsource compliance to a 3rd party vendor and let them manage the program.
d) Have Compliance direct Information Security to fix issues after the auditors report.
02. Your incident response plan should include which of the following?
a) Procedures for litigation
b) Procedures for reclamation
c) Procedures for classification
d) Procedures for charge-back
03. A missing/ineffective security control is identified. Which of the following should be the NEXT step?
a) Perform an audit to measure the control formally
b) Escalate the issue to the IT organization
c) Perform a risk assessment to measure risk
d) Establish Key Risk Indicators
04. Which of the following is a fundamental component of an audit record?
a) Date and time of the event
b) Failure of the event
c) Originating IP-Address
d) Authentication type
05. Within an organization’s vulnerability management program, who has the responsibility to implement remediation actions?
a) Security officer
b) Data owner
c) Vulnerability engineer
d) System administrator
06. The exposure factor of a threat to your organization is defined by?
a) Asset value times exposure factor
b) Annual rate of occurrence
c) Annual loss expectancy minus current cost of controls
d) Percentage of loss experienced due to a realized threat event
07. You have implemented the new controls. What is the next step?
a) Document the process for the stakeholders
b) Monitor the effectiveness of the controls
c) Update the audit findings report
d) Perform a risk assessment
08. In which of the following cases, would an organization be more prone to risk acceptance vs. risk mitigation?
a) The organization uses exclusively a quantitative process to measure risk
b) The organization uses exclusively a qualitative process to measure risk
c) The organization’s risk tolerance is high
d) The organization’s risk tolerance is low
09. When dealing with Security Incident Response procedures, which of the following steps come FIRST when reacting to an incident?
a) Containment
b) Recovery
c) Eradication
d) Escalation
10. Risk appetite directly affects what part of a vulnerability management program?
a) Staff
b) Scope
c) Schedule
d) Scan tools


Question: 01
Answer: b
Question: 02
Answer: c
Question: 03
Answer: c
Question: 04
Answer: a
Question: 05
Answer: d
Question: 06
Answer: d
Question: 07
Answer: b
Question: 08
Answer: c
Question: 09
Answer: a
Question: 10
Answer: b

