712-50 exam dumps

712-50 practice question 285 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 285

Single answerDesign and execute a testing and updating plan for the continuity of operations program

A global healthcare company has updated its continuity of operations program after migrating critical scheduling and patient-record support systems to a hybrid environment. The board has asked the CISO to demonstrate that the program will remain effective as business processes, third-party dependencies, and recovery technologies continue to change. The current program relies mainly on an annual tabletop exercise, and prior lessons learned have not consistently resulted in plan revisions. Which action should the CISO take FIRST to establish an effective testing and updating plan for the continuity of operations program?

  1. A

    Create a risk-based testing strategy that maps critical processes, recovery objectives, technology changes, and third-party dependencies to a schedule of progressively rigorous exercises, with formal after-action reviews and plan updates

  2. B

    Require each business unit to run its own continuity exercise whenever it makes a significant system change, without central coordination, so testing can occur more frequently

  3. C

    Increase the annual tabletop exercise to a two-day workshop for all executives and consider the continuity program validated if leadership agrees that roles and responsibilities are clear

  4. D

    Focus testing on the primary data center and internal IT teams first, because third-party providers are covered by contractual service level agreements and do not need to be included in continuity testing

Show answer and explanation

Correct answer: A

Explanation

The best first step is to establish a structured, risk-based testing and maintenance framework for the continuity of operations program. In a CCISO context, the goal is not merely to run exercises, but to ensure the program remains aligned with business priorities, changing architectures, external dependencies, and recovery requirements. Best practices from business continuity and resilience guidance, including NIST SP 800-34 and ISO 22301/22313 concepts, emphasize that continuity plans should be regularly exercised, reviewed, and updated based on organizational change, test outcomes, and lessons learned. Effective programs include: (1) test scope derived from critical business services and BIA outputs, (2) varying exercise types based on maturity and risk, (3) inclusion of internal and external dependencies, (4) defined success criteria tied to RTO/RPO and operational outcomes, and (5) formal corrective action and document maintenance processes. The scenario specifically highlights weak update discipline after prior tests, so the CISO's priority is to build governance that connects testing results directly to remediation and plan revision.

  • A. Correct.

    Correct. A mature continuity of operations testing and maintenance program should be risk-based, aligned to business impact analysis results, and designed to validate that recovery strategies still support recovery time objectives (RTOs), recovery point objectives (RPOs), critical process priorities, and changing dependencies. Progressive testing typically moves from walkthroughs and tabletop exercises to simulations and operational tests where appropriate. Formal after-action reviews, issue tracking, ownership, and version-controlled updates are essential to ensure lessons learned become plan improvements rather than informal observations.

  • B. Incorrect.

    Incorrect. More frequent testing can be beneficial, but allowing business units to test independently without central governance creates inconsistency in scope, criteria, evidence, and remediation tracking. It also increases the risk that cross-functional dependencies, enterprise priorities, and common failure scenarios are missed. A CISO should implement coordinated governance while still involving business units.

  • C. Incorrect.

    Incorrect. Expanding the tabletop exercise may improve executive engagement, but agreement that roles are clear does not validate the end-to-end effectiveness of continuity capabilities. Tabletop exercises alone do not sufficiently test technical recovery procedures, external dependencies, communications, or execution under realistic conditions. This option also fails to address the recurring weakness that lessons learned have not been translated into controlled updates.

  • D. Incorrect.

    Incorrect. Third-party providers are often critical components of continuity capability in hybrid environments, especially for cloud, telecom, managed security, and application support services. Service level agreements do not by themselves prove recoverability or operational resilience. Excluding external dependencies is a common mistake that leads to unrealistic testing and gaps in recovery planning.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam