712-50 exam dumps

712-50 practice question 255 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 255

Single answer

A global financial services company is consolidating its headquarters and data center access program after a recent audit found that contractors were using borrowed proximity badges to enter restricted areas, and several privileged administrators were still accessing the virtualization management console with only usernames and passwords. The CISO has been asked to recommend the most effective control improvement that reduces both physical and logical access risk without creating unnecessary operational complexity. Which option is the BEST recommendation?

  1. A

    Require a smart ID card plus a biometric factor for entry into restricted physical areas, and enforce MFA for privileged access to the virtualization management console

  2. B

    Replace all physical badges with biometric readers only, because biometrics cannot be shared and therefore eliminate the need for additional logical access controls

  3. C

    Keep proximity badges for physical access, but require stronger password complexity rules for administrators instead of MFA to minimize implementation cost

  4. D

    Issue photo ID cards to all staff and contractors, and rely on security guards to visually verify identities for both data center entry and administrator console access

Show answer and explanation

Correct answer: A

Explanation

The best answer is to implement stronger, risk-based authentication controls in both the physical and logical domains. In the scenario, badge sharing shows that a single-factor physical access system based only on possession is inadequate for restricted areas. Adding a biometric factor increases confidence that the badge holder is the authorized individual. For privileged access to critical systems such as a virtualization management console, MFA is a widely accepted best practice because privileged accounts are high-value targets and passwords alone are insufficient. This recommendation is consistent with guidance from NIST SP 800-63 on digital identity and authentication assurance, NIST SP 800-53 controls such as IA-2 for identification and authentication and PE controls for physical access, and general privileged access management best practices. From a CCISO perspective, the key is selecting controls appropriate to the risk and environment rather than relying on a single mechanism across all situations.

  • A. Correct.

    Correct. This recommendation applies layered controls to the two problem areas identified in the scenario. For restricted physical areas, combining a smart ID card (something you have) with biometrics (something you are) reduces the risk of badge sharing and tailgating-related misuse more effectively than badges alone. For the virtualization management console, MFA is the appropriate improvement because privileged logical access should not rely solely on passwords, which are vulnerable to phishing, reuse, and credential theft. This approach aligns with common security best practices and zero trust principles by strengthening identity assurance in both physical and logical environments.

  • B. Incorrect.

    Incorrect. Biometrics can improve assurance, but replacing badges entirely is not necessarily the best enterprise recommendation. Biometric systems have operational considerations such as enrollment, false rejection rates, privacy, exception handling, and backup access procedures. More importantly, the option incorrectly assumes strong physical authentication removes the need for stronger logical access controls. Physical and logical access risks are separate and both must be addressed, especially for privileged systems.

  • C. Incorrect.

    Incorrect. Stronger password complexity rules do not provide the same risk reduction as MFA for privileged administrator access. Password complexity alone does not adequately address credential theft, phishing, password spraying, or reuse across systems. Keeping badge-only access also fails to address the audit finding that borrowed badges were being used to enter restricted spaces. This option reflects a common misconception that stronger passwords can substitute for MFA in high-risk environments.

  • D. Incorrect.

    Incorrect. Photo ID cards and visual checks may support basic identification, but they are not sufficient as the primary control for high-security areas like a data center, nor are they a valid control for administrator console authentication. Visual inspection is inconsistent, difficult to scale, and vulnerable to human error and social engineering. This option also conflates physical identity verification with logical authentication, which requires technical access controls such as MFA.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam