712-50 exam dumps

712-50 practice question 239 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 239

Single answerSecurity Program Operations (6 questions)

A newly appointed CISO is reviewing security program operations after a ransomware incident exposed several weaknesses. The post-incident review shows that the organization had vulnerability scans running regularly, but critical patches were delayed for weeks because system owners disputed downtime windows, incident triage was inconsistent across regions, and executives received technical metrics that did not clearly show operational risk. The CEO has asked the CISO to improve day-to-day security operations within the next quarter without significantly increasing headcount. Which action should the CISO prioritize FIRST to produce the most immediate and sustainable improvement in security program operations?

  1. A

    Acquire an additional threat intelligence feed to improve visibility into new ransomware campaigns

  2. B

    Establish an operational governance model with defined SLAs, RACI ownership, and risk-based metrics for patching, incident triage, and escalation

  3. C

    Outsource all vulnerability management and incident response activities to a managed security service provider

  4. D

    Increase the frequency of enterprise vulnerability scanning from weekly to daily

Show answer and explanation

Correct answer: B

Explanation

In CCISO-level security program operations, the CISO is expected to address systemic operational weaknesses by aligning people, process, accountability, and metrics with business risk. The scenario shows that the organization already had some technical controls in place, such as vulnerability scanning, but lacked an effective operating model to convert findings into timely action. The most appropriate first priority is to implement operational governance: clearly assign responsibilities, define service level expectations, standardize triage and escalation, and report metrics in a way that communicates business impact.

This aligns with established best practices from sources such as NIST Cybersecurity Framework 2.0, which emphasizes governance, roles, responsibilities, and measurement; NIST SP 800-61 for consistent incident handling processes and escalation; and common vulnerability management practices that stress remediation accountability and risk-based prioritization over raw scan volume. Executive reporting should focus on meaningful indicators such as remediation against SLA by severity, incident mean time to detect/respond/recover, exception aging, and unresolved high-risk exposures. A mature CISO prioritizes operational discipline and accountability before adding more tools, feeds, or providers.

  • A. Incorrect.

    This is not the best first action. Additional threat intelligence may improve awareness of external threats, but the scenario indicates the primary failures were operational execution, ownership, prioritization, and reporting. More intelligence does not resolve delayed patching, inconsistent triage, or poor executive metrics if the underlying operating model is weak.

  • B. Correct.

    This is the best answer. The root causes described are classic security operations governance failures: unclear accountability, inconsistent processes, weak escalation, and metrics that do not support decision-making. Defining service levels, ownership through a RACI model, and risk-based operational metrics creates the structure needed to improve patch management, incident response consistency, and executive reporting without necessarily adding staff. This approach addresses process discipline and business alignment, which are central to effective security program operations.

  • C. Incorrect.

    This is a plausible but incorrect overreaction. Outsourcing can help with capacity or specialized skills, but it does not eliminate the need for internal governance, accountability, and business decision-making. If system owners are disputing downtime windows and executives are receiving poor metrics, those are internal governance issues that a provider alone will not solve. The organization should first fix operational controls and accountability before deciding whether selective outsourcing is needed.

  • D. Incorrect.

    This is not the most effective first step. The organization already performs regular scanning, so the issue is not a lack of vulnerability data. Increasing scan frequency may generate more findings and potentially more operational noise, but it will not fix delayed remediation, ownership disputes, or inconsistent escalation. This option reflects a common misconception that more data collection automatically improves operations.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam