712-50 exam dumps

712-50 practice question 202 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 202

Single answer

A global manufacturing company is replacing its legacy remote access solution with a new VPN platform to support plant engineers, third-party maintenance vendors, and corporate staff. Operations leadership has stated that any new security control must reduce the risk of unauthorized access without delaying emergency maintenance on production systems. During planning, the security team proposes mandatory multifactor authentication (MFA), device posture checks, and time-of-day restrictions for all users. Several plant managers object, noting that vendor support often occurs outside normal hours and from unmanaged devices during critical outages. As the CCISO, which is the BEST next step to ensure the controls are aligned with business needs and are effective before full deployment?

  1. A

    Approve the strongest control set for all user groups, then monitor incident metrics after rollout and adjust if users report major operational issues.

  2. B

    Conduct a business impact and use-case review by user segment, define risk-based access requirements, and run a pilot that tests control effectiveness and operational impact before enterprise deployment.

  3. C

    Delay implementation until all vendors can procure company-managed devices so the control design can remain uniform across all access scenarios.

  4. D

    Implement the controls only for corporate staff first and exempt plant engineers and vendors indefinitely because production availability is the highest priority.

Show answer and explanation

Correct answer: B

Explanation

The best answer is to perform a business-aligned, risk-based design review and validate the proposed controls through pilot testing before full implementation. In executive security leadership, control selection should support organizational objectives, not simply maximize restriction. For remote access, different populations often have different requirements: corporate staff may tolerate stricter posture enforcement, while emergency vendor access may require alternative MFA methods, just-in-time approvals, session monitoring, or tightly scoped exceptions. Before implementation, the CCISO should ensure the design is informed by business process owners, operational constraints, threat scenarios, and risk appetite.

This approach aligns with widely accepted practices from frameworks such as NIST SP 800-53, which emphasizes tailoring security controls to organizational context; NIST SP 800-37 and RMF concepts for selecting, implementing, assessing, and authorizing controls; and ISACA/COBIT governance principles that stress alignment between security controls and enterprise objectives. It also reflects sound change management and testing discipline: pilot testing, user acceptance validation, and effectiveness assessment should occur before broad rollout to confirm that the control mitigates risk without causing unacceptable operational disruption.

  • A. Incorrect.

    This is incorrect because it prioritizes maximum security strength over alignment with operational requirements. A uniform control set may create unacceptable friction for emergency maintenance and vendor access, undermining business objectives. Waiting until after rollout to discover operational failures is poor governance and does not satisfy the requirement to test controls prior to implementation.

  • B. Correct.

    This is correct because it reflects a risk-based, business-aligned control design approach. Segmenting users by operational need allows the organization to tailor controls such as MFA methods, device trust requirements, and conditional access rules to real use cases. A pilot validates both security effectiveness and operational feasibility before broad implementation. This approach is consistent with established practices in change management, security architecture, and control validation.

  • C. Incorrect.

    This is incorrect because it delays risk reduction and assumes uniformity is more important than operational reality. Requiring all vendors to use managed devices may be desirable in some environments, but it is not always feasible for urgent third-party support. The option ignores compensating controls and phased testing strategies that can meet both security and business needs.

  • D. Incorrect.

    This is incorrect because it creates a long-term security gap for the highest-risk access paths. Exempting engineers and vendors indefinitely may protect availability in the short term, but it fails to design controls aligned to the actual risk profile. High availability does not justify avoiding control design and testing; it requires designing appropriate controls that support resilient operations.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam