712-50 exam dumps

712-50 practice question 281 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 281

Single answerDirect contingency planning, operations, and programs to manage risk

A global manufacturing company is consolidating its contingency planning program after several acquisitions. Each business unit has its own disaster recovery procedures, recovery priorities, and third-party recovery contracts. During a recent ransomware incident, the company discovered that several recovery plans conflicted with one another, and some systems with low business value were restored before revenue-generating production systems. The CEO asks the CISO to direct a unified contingency planning program that reduces operational risk and improves resilience across the enterprise. Which action should the CISO take FIRST to best align contingency operations with business risk?

  1. A

    Mandate a single enterprise-wide recovery time objective (RTO) and recovery point objective (RPO) for all critical and noncritical systems to simplify restoration decisions

  2. B

    Conduct a business impact analysis (BIA) and map critical business processes to recovery priorities, dependencies, and supporting assets before standardizing plans

  3. C

    Require all business units to adopt the disaster recovery contract of the largest acquired company because it has the most mature recovery vendor relationship

  4. D

    Invest immediately in additional backup infrastructure and isolated recovery environments to improve the organization's technical recovery capability

  5. E

    Delegate recovery prioritization to individual IT infrastructure managers because they understand system dependencies better than business leaders

Show answer and explanation

Correct answer: B

Explanation

The best first action is to conduct a business impact analysis and use it to drive enterprise recovery priorities. In a CCISO context, directing contingency planning means establishing governance that aligns resilience investments and operational recovery decisions with business risk, not just technical preferences. Best practices from NIST SP 800-34 Contingency Planning Guide for Federal Information Systems and ISO 22301 business continuity guidance emphasize that organizations should first understand business processes, dependencies, and impact tolerances before defining recovery strategies, plans, and testing requirements. A BIA supports rational recovery sequencing, appropriate RTO and RPO assignment, third-party dependency management, and consistent decision-making during crises. In this scenario, the failed ransomware response indicates a governance and prioritization gap, so the CISO should first establish a business-driven foundation before standardizing contracts, mandating recovery objectives, or making new technology investments.

  • A. Incorrect.

    This is incorrect because a single RTO/RPO across all systems is rarely risk-based or economically justified. Different processes and systems have different tolerance for downtime and data loss. Imposing uniform targets can lead to overprotection of low-value assets and underprotection of truly critical services. A common misconception is that standardization alone solves contingency issues, but without understanding business impact, standardization may institutionalize the wrong priorities.

  • B. Correct.

    This is correct because a business impact analysis is the foundational step for directing contingency planning in alignment with enterprise risk. A BIA identifies critical processes, acceptable downtime, upstream and downstream dependencies, legal or contractual obligations, and the assets required to support them. Once this analysis is complete, the CISO can rationalize recovery priorities, standardize plans, and ensure restoration sequencing supports the business rather than isolated technical teams. In the scenario, the core problem is not simply fragmented documentation but the absence of a common business-driven prioritization model.

  • C. Incorrect.

    This is incorrect because selecting a vendor arrangement based on legacy maturity or scale does not ensure alignment with enterprise recovery requirements. The largest acquired company may have a strong contract, but its recovery assumptions, geographic footprint, and service levels may not fit the consolidated organization's risk profile. This option reflects the misconception that inherited operational maturity automatically translates to enterprise suitability.

  • D. Incorrect.

    This is incorrect because improving technical recovery capacity may eventually be appropriate, especially after a ransomware incident, but it is not the first step. Without first determining which business services are most critical and what recovery objectives they require, additional technology investment could be misallocated. This option is attractive because it appears proactive, but it addresses capability before governance and prioritization.

  • E. Incorrect.

    This is incorrect because while infrastructure managers understand technical dependencies, recovery prioritization is ultimately a business decision informed by risk, revenue impact, regulatory obligations, customer commitments, and operational tolerance. Leaving prioritization to IT alone often results in restoring systems based on technical familiarity or ease rather than business criticality. This is a common governance failure in contingency programs.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam