712-50 exam dumps

712-50 practice question 284 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 284

Single answerDesign and execute a testing and updating plan for the continuity of operations program

A global manufacturing company has a continuity of operations program (COOP) for its security operations center, identity services, and ERP platform. The board recently asked the CISO to demonstrate that the program is both testable and maintainable after a regional power disruption exposed outdated call trees, undocumented cloud failover dependencies, and confusion over recovery priorities. The CISO wants a testing and updating plan that improves readiness without causing unnecessary business disruption. Which approach is the MOST appropriate?

  1. A

    Implement an annual full interruption test for all critical services simultaneously, and update the COOP only after the yearly exercise report is approved by executive management.

  2. B

    Establish a risk-based test schedule that uses different exercise types throughout the year, defines success criteria tied to RTO/RPO and recovery dependencies, requires after-action reviews with corrective actions, and updates the COOP whenever significant business, technology, or supplier changes occur.

  3. C

    Outsource all continuity testing to the disaster recovery vendor, since independent testing reduces internal bias and removes the need for business-unit participation in plan maintenance.

  4. D

    Limit testing to technical recovery validation for backup restoration and system failover, because communications, decision authority, and third-party coordination are already covered by incident response procedures.

Show answer and explanation

Correct answer: B

Explanation

The best answer is Option 2 because an effective COOP testing and updating plan must be risk-based, iterative, and integrated with change management. Mature programs do not rely on a single annual event; they use multiple exercise types over time to validate governance, communications, manual workarounds, technical recovery, supplier coordination, and business restoration priorities. The plan should define scope, objectives, participants, prerequisites, metrics, and expected outcomes, including whether RTOs and RPOs are achievable in practice. Just as important, every exercise should produce an after-action review, lessons learned, and corrective actions with owners and deadlines. Plan maintenance should be event-driven as well as periodic, especially after organizational restructuring, infrastructure migration, application changes, new vendors, or facility changes. This approach aligns with widely recognized guidance from NIST SP 800-34 on contingency planning, ISO 22301 on business continuity management systems, and related good practices in resilience governance, which emphasize regular exercising, continual improvement, and plan updates triggered by material change.

  • A. Incorrect.

    This is incorrect because a single annual full interruption test for all critical services at once is unnecessarily disruptive and not aligned with mature continuity testing practices. COOP and business continuity programs typically use a progressive approach, such as checklists, walkthroughs, tabletop exercises, simulations, and selective technical recovery tests, based on risk and operational tolerance. Updating the plan only once a year is also weak governance; plans should be reviewed and updated after tests and after significant changes in business processes, personnel, technology, facilities, or third-party dependencies.

  • B. Correct.

    This is correct because it reflects recognized continuity and resilience best practices. A risk-based testing schedule allows the organization to validate different elements of the COOP with appropriate exercise methods and frequency. Tying test objectives to recovery time objectives (RTOs), recovery point objectives (RPOs), upstream/downstream dependencies, and decision-making processes ensures the test measures whether the organization can actually meet business recovery needs. After-action reviews and tracked corrective actions are essential to continuous improvement. Updating the COOP after significant organizational or technology changes, rather than only on a fixed calendar, addresses the exact gaps identified in the scenario, such as outdated contact data and undocumented dependencies.

  • C. Incorrect.

    This is incorrect because external specialists can support testing, but accountability for continuity capability remains with the organization. Vendor-led testing without business-unit participation misses key elements of continuity, including process workarounds, communications, prioritization, manual procedures, and coordination among internal stakeholders. A common misconception is that technical or vendor testing alone proves organizational continuity readiness; in reality, continuity is cross-functional and requires ownership from business leaders, IT, security, facilities, HR, and third parties as appropriate.

  • D. Incorrect.

    This is incorrect because continuity of operations is broader than technical disaster recovery. Backup restoration and failover testing are important, but the scenario specifically highlights weaknesses in call trees, role clarity, and recovery prioritization. Those are operational and governance issues that must be exercised through tabletop, simulation, and coordination-focused testing. Incident response procedures do not automatically validate continuity decisions, succession, communications, alternate worksites, or third-party recovery interdependencies. Treating continuity as only a technical recovery problem is a common leadership error.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam