712-50 exam dumps

712-50 practice question 273 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 273

Single answerDetermine the value of physical assets and the impact if unavailable

A global manufacturer is consolidating its data centers and asks the CISO to justify continued investment in a legacy on-premises production control server located at its primary plant. The server's book value is only $40,000, but it supports the scheduling system that coordinates raw material intake, robotic assembly timing, and outbound shipments. A recent facilities incident showed that if the server becomes unavailable for more than 6 hours, the plant cannot meet customer delivery commitments, contractual penalties are triggered, and recovery requires specialized vendor support with a 24-hour lead time. Which approach should the CISO use to determine the server's value and communicate the impact of its unavailability to executive leadership?

  1. A

    Value the server primarily by its depreciated purchase price and replacement cost, since physical assets should be assessed using accounting data for consistency.

  2. B

    Value the server based on the business processes and dependencies it enables, including downtime impact, recovery lead time, contractual exposure, and operational disruption, then present the results through a business impact analysis.

  3. C

    Classify the server as low value because it is a legacy asset with a relatively small capital cost, and recommend deferring additional controls until the next asset refresh cycle.

  4. D

    Focus the assessment on the confidentiality of data stored on the server, because information sensitivity is the main driver of asset value in information security programs.

Show answer and explanation

Correct answer: B

Explanation

In CCISO practice, determining the value of a physical asset requires more than looking at purchase price, depreciation, or hardware replacement cost. Executive decision-making should be based on business criticality: what processes the asset supports, what dependencies exist, how quickly the organization must recover, and what financial, legal, operational, safety, or reputational impacts occur if the asset is unavailable. A business impact analysis is the standard way to quantify outage effects such as lost production, missed SLAs, contractual penalties, and recovery constraints. This aligns with widely recognized practices in business continuity and risk management, including NIST guidance on contingency planning and impact analysis (for example, NIST SP 800-34) and ISO 22301/22317 concepts for business impact analysis. The best answer therefore values the physical asset through the business services it enables and communicates that value in business terms leadership can act on.

  • A. Incorrect.

    This is incorrect because limiting valuation to depreciated purchase price or replacement cost ignores the asset's role in critical operations. For physical assets in a security and resilience context, business value includes the processes the asset supports, dependencies, outage consequences, and time to recover. Finance-oriented asset value is relevant, but by itself it significantly understates risk when operational technology or plant systems drive revenue and service delivery.

  • B. Correct.

    This is correct because the scenario clearly shows that the server's business value is far greater than its book value. A sound executive-level assessment should consider operational dependency, maximum tolerable downtime, recovery constraints, contractual penalties, shipment disruption, and downstream business effects. A business impact analysis (BIA) is the appropriate mechanism to translate technical asset unavailability into financial and operational consequences that leadership can use for risk treatment and investment decisions.

  • C. Incorrect.

    This is incorrect because legacy status and low capital cost do not make an asset low value. In fact, legacy systems often create greater business risk due to fragility, scarce support, and long recovery times. Choosing this option reflects the common misconception that age or accounting classification determines criticality, when the more important factor is the asset's contribution to essential business services and the impact if it becomes unavailable.

  • D. Incorrect.

    This is incorrect because confidentiality is only one part of asset valuation. In this scenario, availability is the dominant security objective: the plant cannot meet production and shipping obligations if the server is down. A CISO should evaluate assets using the relevant CIA priorities in context, and here the major loss drivers are operational outage, recovery delay, and contractual impact rather than data sensitivity alone.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam