712-50 Question 210
Single answerA newly appointed CISO reviews the last two quarters of security operations and finds that the same endpoint misconfiguration has contributed to three separate malware incidents. Each incident was closed after the affected devices were reimaged, but there is no evidence of root-cause analysis, no linkage between incidents, and no tracking of whether the underlying control weakness was permanently corrected. Senior leadership asks the CISO to reduce recurrence without slowing down incident response. Which action should the CISO take FIRST to improve remediation and problem management maturity?
- A
Implement a formal problem management process that links related incidents, assigns ownership for root-cause analysis, tracks corrective actions to closure, and measures recurrence trends
- B
Increase the severity rating of all endpoint malware incidents so they receive executive visibility and immediate containment resources
- C
Require the incident response team to keep incidents open until every affected endpoint in the enterprise has been manually validated by security engineers
- D
Outsource endpoint incident handling to a managed security service provider so recurring issues can be addressed by external specialists
Show answer and explanation
Correct answer: A
Explanation
This question tests the CCISO candidate's ability to distinguish between incident management and problem management and to design governance processes that reduce repeat failures. In mature operations, incident management focuses on rapid containment, eradication, and recovery, while problem management focuses on identifying underlying causes of recurring incidents and ensuring permanent corrective actions are implemented. The best first step is to establish a formal problem management process integrated with incident handling. That process should include criteria for identifying repeat events, root-cause analysis, ownership assignment, corrective action plans, closure validation, and metrics such as recurrence rate, mean time to remediation, and overdue remediation items. This aligns with widely accepted service management and security operations practices, including ITIL problem management concepts and control frameworks such as NIST SP 800-61 for incident handling improvement and NIST CSF functions related to response and recovery improvement. From a CCISO perspective, the emphasis is on governance, accountability, and measurable remediation effectiveness rather than only technical response.
- A. Correct.
Correct. The scenario highlights a classic gap between incident management and problem management: incidents are being resolved tactically, but the underlying error is not being analyzed and eliminated. A formal problem management process should identify recurring incidents, perform root-cause analysis, assign accountable owners, document known errors, track remediation tasks, and verify closure. This directly addresses timely recording, analysis, and resolution of errors while preserving rapid incident handling.
- B. Incorrect.
Incorrect. Raising severity may improve visibility and speed of response, but it does not solve the underlying deficiency: the organization is not identifying and removing the root cause of recurring incidents. This option treats symptoms rather than establishing a repeatable remediation and problem management process.
- C. Incorrect.
Incorrect. Keeping incidents open until enterprise-wide manual validation is complete would likely slow incident response and create operational bottlenecks. It also conflates incident resolution with long-term corrective action management. Best practice is to restore service or contain the issue through incident management, then use problem management and corrective action tracking to address systemic weaknesses.
- D. Incorrect.
Incorrect. A service provider may help with operational capacity, but outsourcing does not by itself create internal governance, ownership, or a remediation lifecycle. The core deficiency is the absence of a structured process for linking incidents, analyzing root causes, and ensuring permanent corrective actions are completed and monitored.