712-50 Question 244
Single answerA global manufacturing company is evaluating a cloud-based privileged access management (PAM) solution recommended by a vendor. The vendor states the platform will reduce administrative overhead by replacing the company’s on-premises vault and integrating with identity providers. During the review, stakeholders from operations, legal, identity engineering, and the SOC raise concerns: several production plants rely on legacy systems that cannot support modern authentication methods, some administrator accounts are shared for emergency maintenance, and legal requires that session recordings for EU administrators remain subject to regional data handling restrictions. As the CISO leading the assessment, what is the BEST next step before approving the solution?
- A
Require a structured compatibility and risk assessment that validates legacy system support, shared-account handling, identity integration dependencies, and data residency/legal constraints before any purchase decision
- B
Approve the solution contingent on the vendor’s roadmap commitment to address unsupported legacy systems and regional recording requirements within the next two quarters
- C
Direct the SOC to deploy the solution first for corporate administrators and defer plant and EU concerns until after implementation because risk is already reduced for most users
- D
Reject the solution immediately because any PAM platform that does not natively support all existing systems and jurisdictions is unsuitable for enterprise use
Show answer and explanation
Correct answer: A
Explanation
This question tests the CCISO-level responsibility to engage vendors and internal stakeholders in solution review and to surface incompatibilities, constraints, and risks before procurement or implementation. In this scenario, the key issues span technology, operations, and compliance: legacy systems may not support required agents or authentication methods; shared emergency accounts create workflow and accountability challenges; identity integration may require architectural dependencies such as federation, directory synchronization, or network segmentation changes; and EU session recording raises data residency and privacy considerations. The best action is not to rely on sales claims, defer hard problems, or reject the solution reflexively, but to require a structured compatibility and risk assessment. This aligns with common best practices from enterprise security architecture and third-party risk management: validate requirements against current capabilities, document gaps, assess legal and operational impact, define compensating controls if needed, and make a risk-informed decision. Relevant good practices are reflected in NIST Cybersecurity Framework supply chain and governance concepts, NIST SP 800-53 controls around access enforcement, audit, and system interoperability considerations, and ISO/IEC 27001 practices for supplier relationships, change management, and compliance obligations.
- A. Correct.
Correct. This is the strongest governance-focused response because it addresses the CISO’s role in coordinating vendors and stakeholders to assess recommended solutions and identify incompatibilities, implementation challenges, and compliance issues before approval. A structured assessment should confirm whether the PAM solution can technically support legacy operational technology or server platforms, how it will manage shared or break-glass accounts, what dependencies exist for federation or directory integration, and whether session recording and audit data handling meet regional legal requirements. This approach aligns with due diligence, architecture review, and risk-based decision-making rather than relying on vendor assurances.
- B. Incorrect.
Incorrect. Vendor roadmap commitments are not an adequate substitute for validated current capability when the identified issues affect critical operations and legal compliance. A roadmap may slip, change, or fail to address the organization’s exact use cases. Approving based on future promises creates avoidable operational and regulatory risk, especially where production systems and cross-border data handling are involved. Candidates may choose this option because it appears commercially pragmatic, but it is not the best next step for enterprise risk governance.
- C. Incorrect.
Incorrect. Phased deployment can be appropriate after due diligence, but this option inappropriately minimizes unresolved incompatibilities and compliance concerns. Deferring plant and EU issues until after implementation can create fragmented controls, inconsistent privileged access processes, and potential legal exposure. It also risks selecting a platform that ultimately cannot support a material portion of the enterprise environment. The misconception here is that partial risk reduction justifies moving ahead before confirming enterprise fit.
- D. Incorrect.
Incorrect. Immediate rejection is premature without a formal assessment of whether the concerns can be addressed through supported configurations, compensating controls, scoped deployment, or architectural adjustments. The CISO should first lead a fact-based review with stakeholders and the vendor. This option reflects an overly rigid procurement stance rather than sound evaluation. Rejection may become appropriate later, but not before compatibility, compliance, and operational impact are properly assessed.