712-50 Sample Questions & Answers
Governance, risk, and compliance share top billing with program development, team management, and security operations, rounded out by controls design, audit processes, securing network access controls, and financial and vendor management.
Launch the full 712-50 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Information Security Core Competencies · Application and Data Security
Case Study:
Scenario:
A retail organization is migrating its e-commerce platform to a public cloud provider. The CISO is concerned about the 'Shared Responsibility Model'. The development team wants to use a Function-as-a-Service (FaaS) / Serverless architecture to reduce operational overhead. They plan to process credit card transactions directly within these functions.Constraint:
The organization must remain PCI DSS compliant. The cloud provider is PCI DSS certified.Question:
In this Serverless architecture, which security control remains the SOLE responsibility of the customer (the retail organization)?Show answer & explanation
Correct answer: D
In a FaaS/Serverless model, the cloud provider manages physical security, OS patching, and network infrastructure. The customer is responsible for the security of their code (application logic), data, and the IAM permissions granted to the functions.
- Question 2Beginner
Strategic Planning, Finance, Procurement, and Third-Party Management · Third-Party Risk Management
True or False: In a robust Third-Party Risk Management (TPRM) program, obtaining a vendor's SOC 2 Type II report eliminates the need for the organization to define its own security requirements in the Master Services Agreement (MSA).
Show answer & explanation
Correct answer: B
False. A SOC 2 report validates the vendor's controls against trust principles, but the MSA is a legal contract that must specify the organization's specific requirements, right to audit, breach notification timelines, and SLAs, which the SOC report does not legally enforce.
- Question 3Intermediate
Strategic Planning, Finance, Procurement, and Third-Party Management · Financial Management
An organization is calculating the Return on Security Investment (ROSI) for a new Data Loss Prevention (DLP) solution.
Given:
- Annual Loss Expectancy (ALE) without DLP: $1,000,000
- Estimated mitigation percentage: 80%
- Annual cost of DLP solution: $150,000
What is the ROSI percentage?
Show answer & explanation
Correct answer: A
Calculation:
Savings = ALE * Mitigation = $1,000,000 * 0.80 = $800,000.
Net Benefit = Savings - Cost = $800,000 - $150,000 = $650,000.
ROSI = (Net Benefit / Cost) * 100 = ($650,000 / $150,000) * 100 = 433.33%. - Question 4Beginner
Information Security Core Competencies · Access Control and Identity Management
You are reviewing the Identity and Access Management (IAM) architecture for a hybrid environment. The organization wants to implement Single Sign-On (SSO) across on-premise Active Directory and multiple cloud SaaS applications. Which protocol is the industry standard for exchanging authentication and authorization data between an Identity Provider (IdP) and a Service Provider (SP) in this context?
Show answer & explanation
Correct answer: A
SAML is the standard XML-based protocol for exchanging authentication and authorization data between an Identity Provider (IdP) and a Service Provider (SP), specifically designed for web-based SSO scenarios.
- Question 5Intermediate
Information Security Controls and Audit Management · Security Controls Design
The internal audit team has issued a finding regarding 'Excessive Administrative Privileges' on the corporate network. The IT Director argues that the administrators need these rights to perform their daily tasks efficiently. What is the CISO's best course of action to resolve this conflict while improving security?
Show answer & explanation
Correct answer: A
This is the optimal solution. It addresses the audit finding (reducing standing excessive privileges) while addressing the IT Director's need for efficiency by allowing access when needed (JIT) without permanent admin rights.
- Question 6Advanced
Governance, Risk, Compliance · Compliance Management
A multinational corporation is updating its Data Retention Policy to comply with both GDPR in Europe and various state laws in the US (like CCPA/CPRA). The legal team indicates a conflict: GDPR mandates data minimization and deletion, while certain US financial regulations require data retention for 7 years. Which strategy is most effective for the CISO to recommend?
Show answer & explanation
Correct answer: B
This is the correct approach. When regulations conflict based on geography, the system must be granular enough to apply different rules based on the jurisdiction of the data subject (EU vs US) and the data type (financial records vs marketing data).
- Question 7Intermediate
Information Security Core Competencies · Incident Response and BC/DR
During a Business Impact Analysis (BIA), the CISO identifies that the 'Order Processing System' has a Maximum Tolerable Downtime (MTD) of 4 hours. However, the current Disaster Recovery (DR) solution provides a Recovery Time Objective (RTO) of 12 hours. What is this discrepancy called, and what is the primary risk?
Show answer & explanation
Correct answer: A
The gap between the requirement (MTD 4 hours) and the capability (RTO 12 hours) is an RTO Gap. If the system takes 12 hours to recover but the business dies after 4, the DR plan is insufficient to save the business.
- Question 8Intermediate
Security Program Management & Operations · Program Development
Which of the following is the most effective method for a CISO to ensure that security requirements are included in the early stages of the project management lifecycle (SDLC)?
Show answer & explanation
Correct answer: D
Integrating security gates at the very beginning (Charter/Requirements) ensures 'Security by Design'. Waiting until later phases usually results in costly rework or bolted-on security.
- Question 9Intermediate
Governance, Risk, Compliance · Risk Management
A new CISO discovers that the organization's 'Risk Register' is a static spreadsheet that hasn't been updated in two years. To maturity the risk management program, what should be the immediate next step?
Show answer & explanation
Correct answer: D
Before buying tools or creating complex processes, the CISO must re-baseline the understanding of risk by engaging with the business. A static register is likely outdated; human validation is the critical first step to reviving the process.
- Question 10Advanced
Strategic Planning, Finance, Procurement, and Third-Party Management · Strategic Planning
You are presenting a budget request for a Zero Trust Network Architecture project. The CFO asks, 'Why do we need this if we already have firewalls and VPNs?' Which financial justification aligns best with strategic planning principles?
Show answer & explanation
Correct answer: D
This answer speaks the CFO's language (insurance premiums, liability, enabling remote work business model) rather than just technical features.
Ready for the real thing?
The full 712-50 simulator has every exam-style question, timed mode, and instant scoring.