712-50 exam dumps

712-50 practice question 119 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 119

Single answerAssuring and Alerting Regulators and Examiners

A newly appointed CISO at a regional financial services firm discovers that a third-party payroll provider experienced a breach involving employee personally identifiable information. Initial facts indicate the provider detected the intrusion 10 days ago, but your firm was informed only today. Regulators have an examination scheduled next month, and several state breach notification laws may apply. Senior management is concerned about reputational damage and wants to wait until the forensic investigation is complete before informing regulators or examiners. As the CISO, what is the MOST appropriate course of action?

  1. A

    Advise management to delay any regulatory communication until the forensic report is finalized so the organization can provide complete and verified information

  2. B

    Immediately notify all affected employees first, and defer regulator and examiner communication until legal counsel confirms whether the firm is directly liable

  3. C

    Initiate the incident escalation process, engage legal/compliance to assess applicable notification obligations and timelines, and provide timely, factual notice to regulators and examiners as required, including that the investigation is ongoing

  4. D

    Treat the matter as solely a vendor management issue because the breach occurred at a third party, and document it for the next scheduled examiner meeting

Show answer and explanation

Correct answer: C

Explanation

This question tests executive judgment in assuring and alerting regulators and examiners after a potentially reportable third-party incident. In regulated sectors, the CISO should not wait for perfect information before triggering internal escalation and assessing notification duties. Best practice is to provide timely, factual, and appropriately scoped notice once the organization has a reasonable basis to believe a reportable event may have occurred, while clearly noting that the investigation is ongoing.

This aligns with common supervisory expectations and incident response governance principles: escalate promptly, involve legal/compliance/privacy stakeholders, preserve evidence, assess jurisdiction-specific obligations, and maintain transparent communication with regulators and examiners. For financial institutions, supervisory agencies increasingly expect prompt notification of significant incidents, including those involving service providers. More broadly, many breach notification regimes require notice without unreasonable delay and some impose explicit deadlines. Third-party involvement does not remove accountability; organizations remain responsible for oversight of outsourced services and for communicating material issues to regulators and examiners.

Relevant best-practice sources include regulatory incident notification rules and guidance applicable to the organization, contractual breach-notification clauses with service providers, and governance frameworks such as NIST incident response guidance and third-party risk management expectations from financial regulators. The strongest answer therefore is to activate established processes immediately, assess obligations quickly, and communicate early with updates as facts mature.

  • A. Incorrect.

    This is incorrect because waiting for a final forensic report can cause the organization to miss statutory or supervisory notification deadlines. In many regulated environments, organizations are expected to notify regulators promptly once a reportable incident is identified, even if all facts are not yet known. A common misconception is that notifications should occur only when every detail is confirmed; in practice, initial notifications can be updated as investigations progress.

  • B. Incorrect.

    This is incorrect because employee or consumer notification may be required, but it should not automatically take precedence over regulator or examiner notification where regulatory timelines apply. Whether the firm is directly liable is a legal and regulatory determination that should be assessed immediately, not used as a reason to postpone regulator engagement. This option reflects the misconception that external notifications must happen in a fixed sequence regardless of regulatory requirements.

  • C. Correct.

    This is correct because the CISO's responsibility is to ensure the organization follows its incident response, escalation, and regulatory communication processes without unnecessary delay. The right approach is to coordinate with legal, compliance, privacy, and vendor management teams to determine which laws, contracts, and supervisory expectations apply; then notify regulators and examiners within required timeframes using accurate, qualified facts. It is appropriate to state that the investigation is ongoing and that additional information will follow. This demonstrates sound governance, transparency, and due care.

  • D. Incorrect.

    This is incorrect because incidents at third parties can still create direct regulatory obligations for the contracting organization, especially when customer, employee, or regulated data is involved. Examiners generally expect organizations to oversee third-party risk and to escalate material vendor incidents promptly. Treating this only as a vendor issue ignores the organization's accountability for outsourced services and regulatory expectations around third-party oversight.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam