712-50 exam dumps

712-50 practice question 207 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 207

Single answer

A newly appointed CISO at a global manufacturing company has implemented several information system controls after a ransomware incident, including privileged access management, endpoint detection and response, network segmentation, and a formal vulnerability remediation process. Six months later, the board asks whether these controls are effectively reducing risk and supporting business objectives such as plant uptime and regulatory compliance. The security operations manager proposes reporting the total number of security alerts generated each month as the primary KPI. What should the CISO do FIRST to establish a meaningful control performance monitoring approach?

  1. A

    Adopt the monthly volume of security alerts as the main KPI because it is easy to collect and shows security team activity

  2. B

    Define control-specific metrics and KPIs that map to business objectives and risk reduction outcomes, such as privileged access violations, mean time to remediate critical vulnerabilities, segmentation policy exceptions, and control coverage against critical assets

  3. C

    Wait until the controls have been in place for at least one full year before measuring effectiveness, so there is enough historical data for trending

  4. D

    Report only compliance audit results to the board because audit findings are the most objective measure of control performance

Show answer and explanation

Correct answer: B

Explanation

The best answer is to define control-specific, business-aligned metrics and KPIs rather than relying on generic activity data. In CCISO practice, the CISO must ensure information system controls are not only implemented but also monitored and documented in terms of their contribution to organizational objectives. Effective metrics should be tied to risk scenarios, critical assets, and measurable outcomes such as reduction in exposure, improved resilience, and support for compliance obligations. Good examples include percentage of critical systems covered by EDR, time to revoke privileged access after role changes, percentage of critical vulnerabilities remediated within SLA, rate of unauthorized segmentation changes, and repeat control failure trends. This approach is consistent with common control and governance frameworks such as NIST CSF 2.0, NIST SP 800-55 for performance measurement guidance, COBIT performance management principles, and ISO/IEC 27004 on information security measurement. These sources emphasize selecting metrics that are relevant, repeatable, decision-supportive, and traceable to business and risk objectives rather than simply easy to count.

  • A. Incorrect.

    This is incorrect because alert volume is typically an activity or workload metric, not a meaningful indicator of control effectiveness or business risk reduction. A higher or lower number of alerts may reflect tuning changes, asset growth, or changes in detection logic rather than improved security outcomes. Executives and boards need metrics tied to whether controls are reducing likelihood or impact of risk and supporting objectives such as uptime, resilience, and compliance.

  • B. Correct.

    This is correct because effective monitoring begins with defining metrics that directly evaluate whether controls are operating as intended and achieving desired outcomes. For example, privileged access violations can indicate whether PAM controls are reducing misuse risk; mean time to remediate critical vulnerabilities measures responsiveness of the remediation control; segmentation policy exceptions can show whether network isolation is being maintained; and coverage of critical assets shows whether key controls are actually deployed where risk is highest. This aligns with governance and risk management best practices that require metrics to be risk-based, business-aligned, and actionable.

  • C. Incorrect.

    This is incorrect because the organization should begin measuring control performance as soon as practical after implementation, even if trend data is initially limited. Waiting a full year delays management visibility and reduces the ability to identify gaps, tune controls, and demonstrate progress. Early measurement can include baseline establishment, target setting, and periodic reassessment as data matures.

  • D. Incorrect.

    This is incorrect because audit results are useful but insufficient as the sole measure of control performance. Audits are periodic, often backward-looking, and may focus heavily on design and compliance rather than day-to-day operating effectiveness and business impact. A mature program uses audit outcomes alongside operational metrics, KRIs, KPIs, exception trends, and coverage data.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam