712-50 exam dumps

712-50 practice question 248 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 248

Single answerAccess Control (6 questions)

A global manufacturing company has grown through acquisitions and now operates multiple disconnected identity stores for employees, contractors, and third-party support staff. During an internal audit, the CISO learns that terminated users sometimes retain access to legacy applications for weeks because account provisioning and deprovisioning are handled manually by different business units. The board has directed the security leadership team to reduce unauthorized access risk quickly while also improving auditability and supporting future growth. Which action should the CISO prioritize FIRST to address the root cause of the access control problem?

  1. A

    Implement a centralized identity and access management (IAM) program integrated with authoritative HR processes for joiner-mover-leaver events

  2. B

    Require all privileged users to use multifactor authentication (MFA) when accessing critical systems

  3. C

    Conduct quarterly user access recertification reviews for all business applications

  4. D

    Increase password complexity requirements and reduce password expiration periods across all directories

Show answer and explanation

Correct answer: A

Explanation

The highest-priority action is to establish centralized IAM with automated lifecycle management driven by an authoritative source, typically HR for employees and a controlled sponsor/vendor management source for contractors and third parties. The scenario specifically highlights delayed deprovisioning due to manual, decentralized administration, so the first priority should be a governance and process architecture change rather than a narrower technical control.

From a best-practice standpoint, NIST SP 800-53 controls such as AC-2 (Account Management) emphasize managing the lifecycle of information system accounts, including creation, enabling, modification, disabling, and removal. NIST SP 800-63 also supports strong identity governance practices, while ISO/IEC 27001 and ISO/IEC 27002 stress formal user access provisioning, removal of access rights, and periodic review. In practice, mature organizations centralize identity governance, automate joiner-mover-leaver workflows, integrate with authoritative sources, and then layer on controls such as MFA, privileged access management, and access recertification.

For a CCISO, the key is to identify the control that most effectively reduces enterprise risk at scale. In this case, IAM modernization addresses the root cause, improves auditability, supports mergers and acquisitions integration, and provides a foundation for additional access control capabilities.

  • A. Correct.

    Correct. The core issue is fragmented identity lifecycle management across multiple identity stores, causing delayed deprovisioning and inconsistent provisioning. A centralized IAM program tied to an authoritative source such as HR directly addresses the root cause by standardizing joiner-mover-leaver processes, automating provisioning and deprovisioning, improving segregation of duties oversight, and creating consistent audit trails. From a CCISO perspective, this is the most strategic and scalable response because it reduces operational risk while supporting governance and future acquisitions.

  • B. Incorrect.

    Incorrect. MFA is an important control, especially for privileged access, and it reduces the likelihood of account compromise. However, it does not solve the stated root problem: users who should no longer have access still possess valid accounts. Former employees or contractors with retained access could still authenticate if they have enrolled factors or if access paths do not require MFA. This option treats an authentication-strength issue, not the identity lifecycle governance failure.

  • C. Incorrect.

    Incorrect. Access recertification is a valuable detective and governance control that can identify inappropriate access over time. However, quarterly reviews are periodic and retrospective; they do not provide the timely, automated revocation needed when users leave or change roles. In this scenario, the organization needs to fix the provisioning and deprovisioning process first. Recertification is better positioned as a complementary control after lifecycle automation is established.

  • D. Incorrect.

    Incorrect. Stronger password rules may marginally improve resistance to guessing or reuse, but they do not address stale accounts remaining active after termination. In many modern frameworks, excessive password rotation without risk-based justification can even create usability issues without materially reducing the identified risk. This option reflects a common misconception that password policy changes can compensate for weak identity governance.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam