712-50 exam dumps

712-50 practice question 293 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 293

Single answerUnderstand and manage network cloud security

A global enterprise is migrating several customer-facing applications from its data center to a public cloud provider. The CISO learns that development teams have been creating virtual networks and security rules independently, resulting in inconsistent segmentation, direct internet exposure of administrative services, and limited visibility into east-west traffic. The board has asked for a cloud network security approach that reduces attack surface quickly while supporting multiple business units and future cloud growth. Which action should the CISO prioritize FIRST to establish effective governance and reduce systemic risk?

  1. A

    Implement a cloud network security architecture standard that mandates centralized design patterns for segmentation, ingress/egress control, private administrative access, and logging before allowing further production deployments

  2. B

    Require each application team to select its own preferred cloud-native firewall and web application firewall configuration so teams can optimize for their workloads

  3. C

    Purchase a third-party cloud security tool immediately and defer network architecture decisions until after the tool is deployed and tuned

  4. D

    Allow internet exposure of management ports temporarily, provided multi-factor authentication is enabled for administrators

  5. E

    Focus first on encrypting all virtual machine disks because storage encryption will materially reduce the risk created by insecure network paths

Show answer and explanation

Correct answer: A

Explanation

This scenario is primarily about managing cloud network security at the governance and enterprise architecture level, which aligns closely with CCISO responsibilities. The highest-value first step is to establish and enforce a cloud network security architecture standard before additional production growth increases complexity and exposure. In practice, this baseline typically includes: standardized virtual network design; segmentation by sensitivity and function; default-deny security group or firewall approaches where feasible; tightly governed ingress and egress paths; private administrative access rather than public management interfaces; and mandatory logging, flow logs, and integration with centralized monitoring.

Major cloud providers and recognized security guidance support this approach. AWS best practices emphasize multi-account/network segmentation, least-privilege security groups, avoiding unrestricted management access, and enabling logging such as VPC Flow Logs and CloudTrail. Microsoft Azure guidance similarly emphasizes hub-and-spoke or other governed network topologies, Network Security Groups/Azure Firewall, private endpoints, and centralized monitoring. Google Cloud best practices likewise stress hierarchical policy, VPC firewall governance, segmentation, and Cloud Logging/monitoring. The CIS Benchmarks for AWS, Azure, and GCP also consistently recommend restricting administrative exposure, enabling logging, and enforcing network controls centrally.

From a leadership perspective, the key insight is that the CISO should first solve the systemic issue: lack of governance and standard architecture. Once that baseline exists, the organization can evaluate tooling, automate policy enforcement, and allow limited team-level flexibility within approved patterns.

  • A. Correct.

    Correct. At the CCISO level, the first priority is governance through an enterprise cloud network security architecture and policy baseline. Standardized patterns for segmentation, controlled ingress/egress, private access for administration through bastions/VPN/zero trust access, and required logging/monitoring address the root cause: unmanaged, inconsistent network design across teams. This reduces systemic risk and scales across business units better than isolated technical fixes.

  • B. Incorrect.

    Incorrect. Delegating security architecture decisions entirely to individual teams increases inconsistency and control gaps. While workload-specific tuning is appropriate within guardrails, the enterprise should first establish common standards for network segmentation, exposure, and monitoring. This option reflects the misconception that autonomy alone improves security in multi-cloud or large cloud environments.

  • C. Incorrect.

    Incorrect. Tools can help enforce policy, but they do not replace architecture and governance. Buying a tool before defining target-state network controls often results in partial deployment, policy drift, and poor alignment with business risk. The misconception here is treating technology acquisition as the starting point rather than defining requirements and architecture first.

  • D. Incorrect.

    Incorrect. MFA is valuable, but exposing management ports to the public internet still creates unnecessary attack surface and increases the likelihood of password spraying, exploit attempts, and configuration errors. Best practice is to avoid direct public exposure of administrative interfaces and use private access paths with strong identity controls and logging.

  • E. Incorrect.

    Incorrect. Disk encryption is an important control for protecting data at rest, but it does not address the immediate problem of insecure network exposure, poor segmentation, and lack of east-west visibility. This option reflects a common misunderstanding of control relevance: strong storage security does not compensate for weak network architecture.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam