712-50 exam dumps

712-50 practice question 209 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 209

Single answer

A newly appointed CISO is preparing the annual enterprise security control testing program after the company expanded into cloud-based customer services and outsourced part of its payment processing. Internal audit reported last year that control testing was performed on a fixed annual schedule with little linkage to changes in business risk, and several significant issues were discovered only after a third-party incident. The board has asked for a testing approach that better demonstrates control effectiveness, identifies deficiencies earlier, and aligns with the organization's risk management program. Which action should the CISO take FIRST to improve the control testing program?

  1. A

    Adopt a risk-based testing strategy that prioritizes controls based on current business processes, threat exposure, regulatory obligations, and third-party dependencies, then adjust test frequency and depth accordingly

  2. B

    Increase the number of technical vulnerability scans across all environments so that every control domain is tested monthly

  3. C

    Require each system owner to self-attest quarterly that their assigned security controls are operating effectively

  4. D

    Defer changes to the testing program until the next external audit so the organization can align testing procedures with auditor expectations

Show answer and explanation

Correct answer: A

Explanation

The best answer is to implement a risk-based control testing strategy first. In a mature security governance model, control testing should be driven by the enterprise risk assessment, business impact, threat landscape, compliance requirements, and material changes such as cloud adoption and outsourcing. This is consistent with widely accepted practices in NIST SP 800-53A, which emphasizes assessment procedures for determining whether controls are implemented correctly, operating as intended, and producing the desired outcome, and with ISO/IEC 27001 and ISO/IEC 27004 concepts of monitoring, measurement, analysis, and evaluation tied to information security objectives and risk treatment. From a governance perspective, this also aligns with the Three Lines Model: management owns controls, risk/compliance facilitates oversight, and internal audit provides independent assurance. A CISO should therefore start by redefining the testing program to be risk-based, dynamic, and inclusive of third-party and cloud control dependencies, rather than merely increasing technical scans, relying on self-attestation, or waiting for external auditors.

  • A. Correct.

    Correct. A risk-based testing strategy is the most appropriate first step because it aligns control assurance activities with the organization's risk management program. It ensures testing focuses on areas of greatest risk, including new cloud services, outsourced payment processing, and regulatory exposure. This approach supports effective allocation of resources, increases the likelihood of discovering meaningful deficiencies early, and provides defensible reporting to the board. In practice, this means mapping critical assets, business processes, inherent and residual risks, control objectives, and external dependencies to a testing plan with variable scope and frequency.

  • B. Incorrect.

    Incorrect. Vulnerability scanning is a useful control assessment technique, but it evaluates only a subset of technical controls and does not by itself assess the design and operating effectiveness of broader administrative, detective, preventive, and third-party governance controls. Testing every domain monthly is also not inherently risk-aligned and may waste resources on lower-risk areas while still missing process failures or outsourced control weaknesses.

  • C. Incorrect.

    Incorrect. Self-attestation can be a supplementary monitoring mechanism, but it is not a strong first action for improving assurance. It relies on first-line representations rather than independent validation and is less effective at discovering hidden deficiencies. Organizations sometimes choose this option because it is inexpensive and quick to implement, but it does not address the core audit finding that testing lacked linkage to risk and failed to detect issues early.

  • D. Incorrect.

    Incorrect. Waiting for the next external audit is reactive and inconsistent with management's responsibility to operate an effective internal control assurance program. External auditors may provide useful perspective, but they do not own the organization's security testing strategy. Deferring improvement would prolong known weaknesses in assurance over cloud and third-party environments and would not satisfy the board's request for better alignment with risk management.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam