712-50 exam dumps

712-50 practice question 287 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 287

Single answerUnderstand the importance of integration of IA requirements into the Continuity of Operations Plan (COOP)

A global financial services firm is updating its Continuity of Operations Plan (COOP) after a ransomware incident disrupted access to trading support systems. The operations team wants the revised COOP to focus primarily on restoring business processes at an alternate site within the recovery time objective (RTO). The CISO argues that information assurance (IA) requirements must be explicitly integrated into the COOP rather than handled separately by security operations during the crisis. Which action would BEST demonstrate effective integration of IA requirements into the COOP?

  1. A

    Define alternate-site recovery steps that include identity and access management controls, secure configuration baselines, protection of backup integrity, and validation of system security before business services are resumed

  2. B

    Restore critical applications at the alternate site first and schedule security hardening after operations stabilize so that recovery objectives are not delayed

  3. C

    Keep the COOP limited to business recovery activities and reference the incident response plan for any security-related decisions during continuity events

  4. D

    Require business unit leaders to approve temporary exceptions to security requirements during activation of the COOP in order to speed up service restoration

Show answer and explanation

Correct answer: A

Explanation

The best answer is Option 1 because the purpose of integrating IA requirements into the COOP is to ensure continuity operations preserve confidentiality, integrity, availability, authenticity, and accountability during disruption and recovery. In executive security governance, recovery is not complete if services are restored in an untrusted or noncompliant state. Best practices in continuity and resilience frameworks emphasize that recovery strategies should include security control requirements for alternate processing environments, privileged access, configuration management, backup validation, and system acceptance criteria before returning to operation. This aligns with guidance from NIST SP 800-34 on contingency planning, which stresses coordination between recovery procedures and security considerations, and with broader principles in NIST SP 800-53 contingency planning and system integrity controls. For a CCISO, the key point is governance: IA requirements must be engineered into continuity planning so that recovery teams can execute secure, repeatable, policy-aligned actions under crisis conditions rather than improvising security later.

  • A. Correct.

    This is correct because it embeds IA requirements directly into continuity procedures. Integrating identity and access management, secure baselines, backup integrity checks, and security validation into recovery steps ensures that systems are not only available but also trustworthy, authorized, and resistant to further compromise. In a ransomware scenario, recovering quickly without verifying integrity and access controls could reintroduce malware, enable unauthorized access, or violate regulatory obligations.

  • B. Incorrect.

    This is incorrect because it treats security as a post-recovery activity rather than an integrated recovery requirement. That approach may meet a short-term availability target but can undermine confidentiality, integrity, and compliance. A common misconception is that security controls can be deferred until after restoration; in practice, insecure recovery can expand the incident, especially if compromised images, credentials, or misconfigurations are brought online.

  • C. Incorrect.

    This is incorrect because although incident response and COOP should be aligned, IA requirements cannot be left entirely outside the COOP. Continuity planning must account for how security controls, trust validation, and access restrictions will be maintained during alternate operations. A separate reference alone does not ensure that recovery teams will execute the necessary assurance steps under time pressure.

  • D. Incorrect.

    This is incorrect because ad hoc weakening of security requirements during continuity operations creates governance and risk management problems. While emergency procedures may include preapproved exceptions, the COOP should define controlled, risk-assessed measures in advance rather than relying on business unit leaders to waive protections during a crisis. This option reflects the misconception that speed and assurance are mutually exclusive.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam