712-50 exam dumps

712-50 practice question 208 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 208

Single answer

A newly appointed CISO is reviewing the annual information security control testing program after a payment-processing business unit experienced a significant increase in system changes and third-party integrations. Internal audit reports show that the current testing plan still relies on last year's checklist and tests all control domains on the same annual cycle, regardless of business impact. The board risk committee has asked whether control testing is truly aligned with the organization's risk management program and whether it can identify material control weaknesses early enough to reduce exposure. Which action should the CISO take FIRST to improve the effectiveness of the control testing program?

  1. A

    Map control testing frequency and depth to current risk assessments, including inherent risk, control criticality, recent changes, and third-party dependencies

  2. B

    Increase the sample size for all control tests so that every control domain is tested more thoroughly during the annual review

  3. C

    Outsource all technical control testing to an external assessor to ensure independence and remove management bias

  4. D

    Focus testing on controls that failed in the prior year because those are the most likely to fail again

Show answer and explanation

Correct answer: A

Explanation

The best first action is to redesign the testing program so that it is driven by current enterprise and operational risk information rather than a static annual checklist. In practice, this means linking test frequency, scope, and rigor to factors such as inherent risk, residual risk, asset criticality, regulatory impact, recent changes, prior incidents, control maturity, and reliance on third parties. This is consistent with widely accepted governance and assurance practices in frameworks such as NIST SP 800-53A, which emphasizes assessment procedures for determining whether controls are implemented correctly, operating as intended, and producing the desired outcome, and with ISO/IEC 27001 and ISO/IEC 27004 concepts around monitoring, measurement, and evaluation of information security performance. It also aligns with a risk-based internal control philosophy reflected in frameworks like COBIT and COSO, where assurance activities should be tied to organizational objectives and risk appetite. The key CCISO principle being tested here is executive ownership of a risk-aligned security assurance program: effective control testing is not merely about doing more testing, but about testing the right controls, at the right depth, at the right time.

  • A. Correct.

    This is correct because an effective control testing program should be risk-based and aligned with the organization's risk management process. When business conditions change, such as increased system changes and new third-party integrations, the testing strategy should be recalibrated based on current risk levels, control importance, threat exposure, and change activity. This approach improves the likelihood of discovering meaningful deficiencies early and ensures testing resources are applied where they matter most.

  • B. Incorrect.

    This is incorrect because increasing sample sizes uniformly may improve coverage in a narrow sense, but it does not address the core problem: the testing plan is not aligned to current risk. Testing all areas more deeply can consume resources without materially improving assurance if low-risk controls receive disproportionate attention while high-risk, recently changed controls remain under-prioritized.

  • C. Incorrect.

    This is incorrect because independent assessment can be valuable, especially for high-risk or specialized technical areas, but outsourcing all technical testing is not the first step and does not by itself ensure alignment with the risk management program. The CISO must first define a risk-based testing strategy; only then should sourcing decisions be made about who performs specific tests.

  • D. Incorrect.

    This is incorrect because prior failures are relevant inputs, but focusing mainly on last year's failed controls creates a backward-looking program. It may miss emerging risks introduced by new technologies, business processes, or vendors. A mature testing program considers prior deficiencies along with current risk assessments, business changes, threat intelligence, and control criticality.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam