712-50 exam dumps

712-50 practice question 118 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 118

Single answerAssuring and Alerting Regulators and Examiners

A newly appointed CISO at a regional financial services firm discovers that a third-party managed file transfer platform used for customer records was compromised two weeks earlier. Initial investigation shows that unauthorized parties may have accessed personally identifiable information for customers in multiple states, and the firm is currently under routine examination by its primary financial regulator. Forensic analysis is still ongoing, and the exact number of affected records is not yet confirmed. The CEO wants to wait until the investigation is complete before informing any external parties to avoid reputational damage from an incomplete disclosure. What should the CISO do FIRST to best meet regulatory and examiner expectations?

  1. A

    Advise leadership to notify legal counsel, activate the incident response and breach notification process, and make a timely regulator notification based on known facts, while clearly stating that the investigation is ongoing

  2. B

    Wait for forensic investigators to determine the exact scope and root cause before communicating with regulators so the organization can provide a complete and accurate report

  3. C

    Inform the board and internal audit first, but defer regulator notification until customer notifications are ready to be issued at the same time

  4. D

    Prepare a public statement and customer FAQ immediately, and notify regulators only after external communications are finalized to ensure message consistency

Show answer and explanation

Correct answer: A

Explanation

This question tests the CISO's judgment in assuring and alerting regulators and examiners during an evolving incident. In practice, the correct approach is to notify appropriate internal stakeholders immediately, engage legal and compliance functions, and provide timely notice to regulators based on the facts currently available, while explicitly stating that the investigation is ongoing and updates will follow. This aligns with common regulatory expectations in financial services and privacy governance: prompt escalation, transparency, preservation of evidence, and accurate but not unnecessarily delayed reporting.

Best practices reflected here include those found across incident response and governance frameworks such as NIST Computer Security Incident Handling Guide (SP 800-61), which emphasizes predefined reporting and coordination procedures, and sector-specific supervisory expectations that require timely reporting of significant cyber incidents. In financial services, examiners commonly assess whether management had effective escalation paths, whether legal/regulatory obligations were understood, and whether reporting was timely, accurate, and updated as new information emerged. The key leadership principle is that the CISO should not let the pursuit of perfect information delay mandatory or expected initial notification.

  • A. Correct.

    Correct. In regulated environments, the CISO should ensure the organization follows its incident response, legal, and breach notification procedures promptly and escalates to regulators/examiners without unnecessary delay when a potentially reportable incident is identified. Regulators generally expect timely notification based on currently known facts, with updates as the investigation develops. This demonstrates good faith, effective governance, and control maturity. The CISO should coordinate with legal, privacy, compliance, and executive leadership, but should not delay initial regulatory notice solely to achieve perfect completeness.

  • B. Incorrect.

    Incorrect. Waiting for full forensic certainty is a common mistake. Many regulatory regimes and examiner expectations are built around timely initial notice followed by supplemental updates as material facts become clearer. Delaying until all details are known can create the appearance of weak governance, poor escalation, or concealment, especially in financial services and privacy-regulated environments.

  • C. Incorrect.

    Incorrect. Informing the board and internal audit is important from a governance perspective, but deferring regulator notification until customer communications are prepared is not the best first action. Regulatory notification timelines may be shorter or independent of customer notification timing. Examiners typically expect prompt escalation once a potentially significant incident is identified, even if customer messaging is still being developed.

  • D. Incorrect.

    Incorrect. Public relations sequencing should not drive regulatory reporting decisions. Customer and media communications should be coordinated, but regulators and examiners generally expect early, direct notification through established channels. Prioritizing public messaging over regulator engagement can undermine trust and may increase supervisory concern.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam