712-50 exam dumps

712-50 practice question 205 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 205

Single answer

A global manufacturing company is rolling out a new ERP platform that will process financial, procurement, and supplier data across 12 countries. Internal audit found that prior control implementations failed because security requirements were added late, regional IT teams lacked database security expertise, and logging infrastructure could not support centralized monitoring. As the newly appointed CISO, you must recommend the MOST effective resource strategy to implement and sustain information systems controls for the ERP environment before go-live. Which approach is BEST?

  1. A

    Assign control ownership to the ERP project manager, rely on the software vendor's default security settings, and defer centralized logging until after stabilization to avoid delaying deployment.

  2. B

    Build a cross-functional control implementation plan that maps required controls to specific resources, including ERP security architects, database administrators, SOC/logging capacity, IAM integration support, regional process owners, and documented data flow and asset inventories.

  3. C

    Outsource all ERP security responsibilities to a managed security service provider (MSSP), since third-party specialists can operate the controls more efficiently than internal teams.

  4. D

    Prioritize procurement of additional security tools for the ERP platform first, because technology gaps are the primary reason enterprise control programs fail.

Show answer and explanation

Correct answer: B

Explanation

The best answer is the cross-functional resource plan because CCISO-level decision making requires selecting and aligning the resources necessary to implement and sustain controls across people, process, information, and technology domains. In this scenario, the failure points are explicitly resource-related: security was engaged too late, teams lacked database expertise, and logging infrastructure was insufficient. Therefore, the strongest response is not simply assigning a project owner, buying tools, or outsourcing everything, but deliberately identifying the human capital, information, infrastructure, and architectural support required for the ERP control environment.

This aligns with widely accepted security and governance practices. NIST SP 800-53 emphasizes that controls depend on organizational roles, system components, and supporting operational capabilities, not just technical settings. NIST Cybersecurity Framework 2.0 highlights governance, asset management, and role alignment as foundational to implementing security outcomes. COBIT guidance similarly stresses that enterprise governance requires defined responsibilities, enablers, and supporting information flows. In practice, a CISO should ensure that control implementation for a major business platform includes: accountable control owners, skilled administrators for the relevant technologies, documented data flows and asset inventories, integration with IAM and logging/monitoring, and sufficient operational capacity to maintain controls after deployment.

  • A. Incorrect.

    This is incorrect because it underestimates the range of resources required to implement and maintain effective controls. Control ownership should align with accountable business and technical stakeholders, not rest primarily with a project manager who may not own operational risk after go-live. Relying on vendor defaults is a common mistake; defaults rarely address an organization's specific regulatory, segregation-of-duties, logging, IAM, and monitoring requirements. Deferring centralized logging also weakens detective and incident response capabilities at a critical stage.

  • B. Correct.

    This is correct because it addresses the full set of resources needed for sustainable control implementation: human capital (security architects, DBAs, IAM specialists, regional process owners), information resources (data flows, asset inventories, control requirements), and infrastructure/architecture resources (logging/SOC capacity, ERP integration points, database and platform support). It also reflects a governance-driven approach in which controls are mapped to business processes and operating ownership before go-live. This directly mitigates the audit findings that prior failures stemmed from late security involvement, skills gaps, and insufficient monitoring infrastructure.

  • C. Incorrect.

    This is incorrect because outsourcing can supplement internal capability, but it does not remove the organization's accountability for control design, risk acceptance, business process ownership, and governance. An MSSP typically supports monitoring or selected operational controls, but ERP-specific access models, segregation-of-duties decisions, data classification, and process-level ownership still require internal business and technical stakeholders. Choosing this option reflects the misconception that security accountability can be fully transferred to a third party.

  • D. Incorrect.

    This is incorrect because tool acquisition alone does not solve deficiencies in staffing, process ownership, architectural integration, or control design. Many control failures occur not from a lack of tools but from poor alignment among people, data, processes, and supporting infrastructure. Buying technology first without confirming who will configure, maintain, monitor, and govern it often creates shelfware or ineffective controls.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam