712-50 Question 245
Single answerA global manufacturing company is evaluating a vendor-recommended cloud access security broker (CASB) to improve visibility and control over SaaS usage. During the review, the CISO learns that the proposed solution relies on inline proxy deployment and API integrations. Key stakeholders report that several business-critical engineering applications use certificate pinning, some remote sites have high network latency, and the identity team is in the middle of a phased migration from one identity provider to another. The vendor states the solution can be implemented within 30 days if the company adopts the vendor’s standard architecture. What should the CISO do FIRST to properly assess the recommendation and identify incompatibilities or implementation risks?
- A
Approve a limited deployment immediately so the organization can validate security improvements while addressing technical issues after go-live
- B
Require a structured compatibility and dependency assessment with network, identity, application, and business stakeholders before approving the vendor’s architecture
- C
Reject the solution because certificate pinning and identity platform migration make inline CASB deployments unsuitable in all cases
- D
Ask procurement to renegotiate the implementation timeline and price before conducting any further technical review
Show answer and explanation
Correct answer: B
Explanation
The best answer is to require a structured compatibility and dependency assessment involving the relevant stakeholders before approving the proposed solution. In CCISO practice, senior security leaders are expected to participate with vendors and internal stakeholders to evaluate recommended solutions for operational fit, integration dependencies, business impact, and hidden implementation risks. In this scenario, the vendor’s standard architecture may conflict with real environmental conditions. Inline proxy approaches can be affected by certificate pinning in some applications; remote site latency may create performance or user experience issues; and identity provider migration introduces change risk for authentication flows, policy mapping, and support processes. Best practice is to validate assumptions through architecture review, stakeholder workshops, data flow analysis, dependency mapping, pilot criteria, and exception planning. This aligns with common governance and architecture review principles reflected in sources such as NIST SP 800-53 supply chain and system integration considerations, NIST SP 800-161 on supply chain risk management, and general enterprise security architecture review practices. The CISO’s responsibility is not simply to accept vendor claims or reject solutions outright, but to ensure decisions are based on documented compatibility, business impact, and implementation feasibility.
- A. Incorrect.
This is incorrect because moving into deployment before validating architecture fit, dependencies, and operational constraints creates avoidable risk. A limited rollout can be useful later as a pilot, but only after the organization has assessed whether certificate pinning, latency-sensitive sites, identity migration, and application integration constraints could break functionality or create unacceptable business impact.
- B. Correct.
This is correct because the scenario contains multiple indicators of potential incompatibility: certificate pinning may interfere with inline proxy controls, high-latency sites may experience degraded performance, and an identity provider migration can affect authentication, policy enforcement, and integration stability. A CISO should first convene the relevant stakeholders and require a formal review of technical dependencies, business process impacts, exception handling, and deployment assumptions before accepting a vendor’s standard architecture.
- C. Incorrect.
This is incorrect because it overgeneralizes. Certificate pinning and identity migration are significant concerns, but they do not automatically make the solution unworkable in every environment. There may be compensating architectures, phased deployment options, selective bypass approaches, API-only coverage for certain apps, or sequencing adjustments. The role of the CISO is to ensure a disciplined assessment rather than making a premature blanket rejection.
- D. Incorrect.
This is incorrect because commercial negotiation is not the first priority when there are unresolved architectural and operational questions. Timeline and pricing matter, but they should be addressed after the organization understands whether the solution is compatible with the environment and what deployment model, scope, or compensating controls are actually needed.