712-50 exam dumps

712-50 practice question 246 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 246

Single answerDomain 4: Information Security Core Competencies (46%)

A global manufacturing company is modernizing its identity and access management program after an internal audit found excessive standing privileges in its ERP environment and delayed termination of third-party access. The board has asked the CISO to reduce the risk of fraud and unauthorized system changes without disrupting plant operations that run 24/7. The environment includes employees, contractors, and managed service providers with access to finance, procurement, and production support systems. Which approach should the CISO prioritize to most effectively address the audit findings while maintaining operational continuity?

  1. A

    Implement a privileged access management (PAM) program with just-in-time elevation, approval workflows for sensitive access, session monitoring, and integration with joiner-mover-leaver processes

  2. B

    Require all users to change passwords every 30 days and increase minimum password length for ERP and production support accounts

  3. C

    Perform a one-time manual review of all privileged accounts and remove excess access, then repeat the exercise during the next annual audit cycle

  4. D

    Separate the ERP environment from the production network using additional firewalls and restrict administrative access to on-premises devices only

Show answer and explanation

Correct answer: A

Explanation

The scenario centers on identity governance and privileged access management, both core information security competencies for a CCISO. The most effective response is to prioritize a control strategy that addresses the root causes: excessive standing privileges and delayed deprovisioning across a mixed user population. A mature PAM capability combined with joiner-mover-leaver integration supports least privilege, just-in-time access, monitoring, accountability, and timely removal of access when roles change or contracts end. This approach also helps preserve operational continuity in a 24/7 environment by allowing controlled elevation when needed rather than broad permanent rights. Relevant best practices can be found in NIST SP 800-53, especially AC-2 Account Management, AC-3 Access Enforcement, AC-5 Separation of Duties, AC-6 Least Privilege, and AU controls for logging and monitoring. ISO/IEC 27001 and 27002 also emphasize access control, privileged access restriction, and timely removal or adjustment of access rights.

  • A. Correct.

    Correct. This directly addresses both excessive standing privileges and delayed deprovisioning in a sustainable way. A PAM program with just-in-time access reduces persistent privileged rights, approval workflows enforce governance over elevated access, and session monitoring improves accountability and detection. Integration with joiner-mover-leaver processes helps ensure timely provisioning and deprovisioning for employees, contractors, and third parties. This is aligned with least privilege, separation of duties, and lifecycle-based identity governance practices commonly referenced in NIST SP 800-53 controls such as AC-2 (Account Management), AC-5 (Separation of Duties), AC-6 (Least Privilege), and IA-related controls.

  • B. Incorrect.

    Incorrect. Stronger password requirements may marginally improve authentication strength, but they do not solve the core issues identified by the audit: excessive standing privileges and delayed removal of access. In addition, frequent forced password changes can create usability and operational issues without materially improving access governance if not tied to risk-based controls. The misconception here is equating authentication hardening with authorization and lifecycle management.

  • C. Incorrect.

    Incorrect. A one-time cleanup may temporarily reduce exposure, but it does not establish an operational control framework to prevent recurrence. Given the company has continuous operations, changing personnel, and third-party involvement, access risk must be managed as an ongoing process. The misconception is treating identity governance as a periodic audit task instead of a continuous control function.

  • D. Incorrect.

    Incorrect. Network segmentation and tighter administrative pathways can reduce attack surface and are valuable defense-in-depth measures, but they do not primarily resolve standing privilege abuse or delayed termination of authorized users. A former contractor with valid credentials could still retain inappropriate access if account governance is weak. The misconception is assuming infrastructure controls can substitute for identity and privilege management.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam