712-50 exam dumps

712-50 practice question 257 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 257

Single answerUnderstand the importance of warning banners for implementing access rules

A newly appointed CISO is reviewing the organization's remote access controls after legal counsel reports difficulty pursuing insider misuse cases. Investigators found that employees and contractors could log in to critical systems without seeing any notice about authorized use, monitoring, or consent to inspection. The CISO wants a control that strengthens the organization's ability to enforce access rules and support disciplinary or legal action without significantly changing authentication workflows. Which action is the MOST appropriate?

  1. A

    Implement a pre-login warning banner stating the system is for authorized use only, that activity may be monitored, and that proceeding indicates consent to monitoring and enforcement of policy

  2. B

    Display a general security awareness message after login reminding users to protect passwords and report suspicious activity

  3. C

    Add a confidentiality disclaimer to all outbound email so users are informed that company information is sensitive

  4. D

    Require users to reaccept the acceptable use policy annually in the HR portal instead of placing notices on systems they access

Show answer and explanation

Correct answer: A

Explanation

Warning banners are important because they operationalize access rules at the moment of access. A well-designed pre-login banner typically states that the system is for authorized use only, that use may be monitored, recorded, and subject to audit, and that unauthorized use is prohibited and may result in disciplinary action or prosecution. This helps set user expectations, supports policy enforcement, and can strengthen the organization's legal posture by reducing a user's claim to an expectation of privacy on organizational systems. From a governance perspective, banners should be coordinated with legal counsel, HR, and privacy requirements to ensure wording is appropriate for the jurisdiction and user population. This approach is consistent with widely recognized security control guidance such as NIST SP 800-53 control AC-8 (System Use Notification), which recommends displaying an approved system-use message before granting access.

  • A. Correct.

    Correct. A pre-login warning banner is the strongest choice because it directly supports access-rule enforcement at the point of system entry. It establishes that the system is restricted to authorized users, notifies users that activity may be monitored, and documents implied or explicit consent before access is granted. This can improve the organization's position in administrative, civil, and sometimes criminal matters by reducing claims of privacy expectations or lack of notice. It also aligns with common control guidance that login notices should precede access, not follow it.

  • B. Incorrect.

    Incorrect. A post-login awareness message may be useful for education, but it is weaker from an enforcement perspective because the user has already accessed the system before seeing the notice. That limits its value for establishing conditions of access and consent to monitoring. Candidates might choose this because it seems less disruptive, but it does not address the legal and policy enforcement gap identified in the scenario.

  • C. Incorrect.

    Incorrect. An email confidentiality disclaimer addresses external communication handling, not system access control. It does not notify users at the time they access protected systems, nor does it help establish consent to monitoring of system use. This distractor reflects a common misconception that any legal-style disclaimer improves enforceability across all security contexts.

  • D. Incorrect.

    Incorrect. Annual acceptable use policy acknowledgment is important for governance and employee accountability, but by itself it is not a substitute for a system login warning banner. HR portal acknowledgment is disconnected from the actual access event and does not provide immediate notice at the time of system use. Someone might choose this because policy acceptance is valuable, but it does not best solve the specific issue of enforcing access rules during system login.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam