712-50 Question 211
Single answerA newly appointed CISO reviews the past six months of security incidents and finds that the same endpoint misconfiguration has caused three separate malware outbreaks. Each incident was contained quickly, but post-incident reviews were inconsistent, corrective actions were tracked in spreadsheets, and there is no formal process to verify that the underlying issue was eliminated across business units. The CIO asks for a process improvement that will reduce recurrence and provide executive visibility into remediation effectiveness. Which action should the CISO implement FIRST to best address this deficiency?
- A
Establish a formal problem management process that requires root cause analysis, assignment of problem owners, documented corrective actions, target dates, and validation of closure through metrics and trend reporting
- B
Increase the endpoint detection and response tool sensitivity so future malware outbreaks are detected earlier and can be contained faster
- C
Require the incident response team to produce a lessons-learned report after every malware event, but allow business units to decide whether to implement the recommendations
- D
Delegate remediation tracking to each regional IT manager and request monthly email updates for the audit committee
Show answer and explanation
Correct answer: A
Explanation
This scenario tests the distinction between incident management and problem management. Incident management focuses on restoring operations and containing immediate harm, while problem management focuses on identifying and eliminating the root cause of recurring incidents. A CCISO should recognize that repeated malware outbreaks from the same endpoint misconfiguration indicate a systemic deficiency in remediation governance, not simply a tooling issue. The best first step is to implement a formal problem management process with root cause analysis, documented corrective actions, named owners, due dates, validation testing, and management reporting.
This approach aligns with widely accepted practices from IT service management and security governance. ITIL problem management emphasizes recording problems, performing root cause analysis, maintaining workarounds and known errors where applicable, and ensuring permanent resolution. From a control and governance perspective, NIST guidance and audit best practices also support formal Plans of Action and Milestones (POA&M)-style tracking, accountability, and verification of remediation effectiveness. Executive metrics such as repeat incident rate, overdue remediation items, mean time to remediate root causes, and closure validation rates are especially valuable to demonstrate whether the organization is actually reducing risk rather than merely responding to symptoms.
- A. Correct.
Correct. The core issue is not detection or containment speed, but repeated recurrence due to the absence of a structured process for identifying and eliminating underlying causes. A formal problem management process addresses exactly this gap by ensuring errors and deficiencies are recorded, analyzed, assigned to accountable owners, remediated within defined timelines, and validated before closure. Including metrics and trend reporting also gives executive leadership visibility into whether recurrence is decreasing and whether remediation is effective across business units.
- B. Incorrect.
Incorrect. Improving EDR sensitivity may shorten detection time, but it does not address the repeated underlying misconfiguration that is causing the outbreaks. This is a common mistake: optimizing incident response controls when the larger governance issue is weak problem management and deficiency remediation. The scenario specifically highlights recurrence and lack of verification, which this option does not solve.
- C. Incorrect.
Incorrect. Lessons-learned reports are useful, but this option is insufficient because it makes remediation discretionary. Without mandatory ownership, centralized tracking, deadlines, and validation, the organization will likely continue to see repeated failures. Candidates may choose this because post-incident reviews seem relevant, but reviews alone are not a complete remediation process.
- D. Incorrect.
Incorrect. Decentralized tracking through email updates and regional managers creates inconsistency, weak accountability, and poor auditability. It also makes it difficult to aggregate trends, verify closure, and ensure enterprise-wide remediation. This reflects an immature control environment and does not provide the disciplined problem management capability the scenario requires.