Free 712-50 sample questions
Real questions from the Certified Chief Information Security Officer (CCISO) practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
A global healthcare provider is acquiring a smaller regional hospital network. During the due diligence phase, you identify that the target company uses a legacy EMR system that cannot be patched against several critical vulnerabilities. The business strategy relies on integrating this network within 90 days. What is the most appropriate governance approach to handle this risk?
You are establishing a new Enterprise Risk Management (ERM) framework. You need to define the process for risk treatment decisions. Review the diagram below representing the decision logic. Which logic flow correctly represents the standard risk treatment methodology based on ISO 31000 principles? flowchart TD Start[Risk Identified] --> Assess{Risk > Appetite?} Assess -->|No| A[Monitor] Assess -->|Yes| Cost{Cost of Control < Impact?} Cost -->|Yes| B[Treat/Mitigate] Cost -->|No| Crit{Is Risk Critical?} Crit -->|Yes| C[Transfer/Avoid] Crit -->|No| D[Accept]
Which of the following documents is the PRIMARY source for an external auditor to determine if an organization's security controls are operating effectively over a period of time?
A CISO is designing a Key Performance Indicator (KPI) dashboard for the executive team. The goal is to measure the efficiency of the Incident Response (IR) team. Which TWO metrics would provide the most meaningful insight into operational efficiency? (Select TWO)
Case Study: Scenario: A retail organization is migrating its e-commerce platform to a public cloud provider. The CISO is concerned about the 'Shared Responsibility Model'. The development team wants to use a Function-as-a-Service (FaaS) / Serverless architecture to reduce operational overhead. They plan to process credit card transactions directly within these functions. Constraint: The organization must remain PCI DSS compliant. The cloud provider is PCI DSS certified. Question: In this Serverless architecture, which security control remains the SOLE responsibility of the customer (the retail organization)?
True or False: In a robust Third-Party Risk Management (TPRM) program, obtaining a vendor's SOC 2 Type II report eliminates the need for the organization to define its own security requirements in the Master Services Agreement (MSA).
An organization is calculating the Return on Security Investment (ROSI) for a new Data Loss Prevention (DLP) solution. Given: - Annual Loss Expectancy (ALE) without DLP: $1,000,000 - Estimated mitigation percentage: 80% - Annual cost of DLP solution: $150,000 What is the ROSI percentage?
You are reviewing the Identity and Access Management (IAM) architecture for a hybrid environment. The organization wants to implement Single Sign-On (SSO) across on-premise Active Directory and multiple cloud SaaS applications. Which protocol is the industry standard for exchanging authentication and authorization data between an Identity Provider (IdP) and a Service Provider (SP) in this context?
The internal audit team has issued a finding regarding 'Excessive Administrative Privileges' on the corporate network. The IT Director argues that the administrators need these rights to perform their daily tasks efficiently. What is the CISO's best course of action to resolve this conflict while improving security?
10 more free samples are waiting
Create a free account to unlock the whole 712-50 sample bank, or get full access to all 216 practice questions in the simulator.