712-50 exam dumps

712-50 practice question 179 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 179

Single answerResilience During Uncertain Environment

A global manufacturing company is operating during a period of geopolitical instability, energy price volatility, and increased ransomware activity. The board has asked the CISO to improve cyber resilience without significantly increasing budget. The company relies on a small number of critical suppliers for plant operations and has several legacy systems that cannot be quickly replaced. Which action should the CISO prioritize FIRST to improve resilience during this uncertain environment?

  1. A

    Conduct an enterprise-wide resilience assessment to identify critical business services, map dependencies on suppliers and legacy systems, and align recovery priorities with business impact

  2. B

    Purchase a larger cyber insurance policy to transfer the increased operational and cyber risk exposure

  3. C

    Accelerate replacement of all legacy systems, even if it requires pausing other security initiatives and exceeds the current fiscal plan

  4. D

    Increase the frequency of phishing simulations and awareness training for all employees to reduce the likelihood of ransomware infection

Show answer and explanation

Correct answer: A

Explanation

The best first step is to perform a business-driven resilience assessment that identifies critical services, supporting assets, key personnel, third-party dependencies, and realistic recovery requirements. In uncertain environments, CISOs should prioritize actions that strengthen the organization's ability to withstand, adapt to, and recover from disruption rather than focusing on a single threat or a purely financial transfer mechanism. This aligns with established practices in business continuity and cyber resilience, including business impact analysis and dependency mapping as described in frameworks such as NIST Cybersecurity Framework 2.0, NIST SP 800-34 for contingency planning, ISO 22301 for business continuity management systems, and guidance from operational resilience programs. Once critical dependencies and recovery priorities are known, the organization can make cost-effective decisions such as segmenting legacy systems, validating offline backups, diversifying suppliers, implementing compensating controls, and refining incident response and disaster recovery plans.

  • A. Correct.

    Correct. In an uncertain environment, the first priority is to understand what must be protected and recovered first. A resilience assessment that identifies critical business services, maps internal and third-party dependencies, and establishes business-aligned recovery priorities gives leadership the basis for risk-informed decision-making under constrained budget conditions. This is consistent with resilience and business continuity best practices such as business impact analysis, dependency mapping, and prioritization of crown-jewel services before selecting or funding specific controls.

  • B. Incorrect.

    Incorrect. Cyber insurance may help offset some financial loss, but it does not improve operational resilience by itself. Insurance does not reduce dependency concentration, improve recoverability, or address single points of failure in suppliers and legacy environments. Choosing insurance first reflects a common misconception that risk transfer can substitute for resilience planning and control improvement.

  • C. Incorrect.

    Incorrect. Replacing all legacy systems may eventually reduce risk, but doing so immediately is usually unrealistic, costly, and disruptive, especially when budget growth is limited. A CISO should first determine which legacy assets support critical services and where compensating controls, segmentation, backup validation, or alternative operating procedures provide better short-term resilience. This option confuses a long-term modernization strategy with the first action required in crisis-oriented resilience planning.

  • D. Incorrect.

    Incorrect. Security awareness and phishing simulations can reduce one attack vector, but they are only one tactical measure and do not address the broader resilience problem presented in the scenario, including supplier concentration, legacy system dependency, and recovery prioritization. This choice reflects the common error of focusing narrowly on prevention instead of balancing prevention, response, recovery, and continuity.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam