712-50 exam dumps

712-50 practice question 302 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 302

Single answerUnderstand the concept of network segmentation

A newly acquired subsidiary is being integrated into the enterprise network. During due diligence, the CISO learns that the subsidiary's manufacturing environment includes legacy systems that cannot be patched quickly and must continue communicating with a small set of application servers and vendor support endpoints. The board is concerned about ransomware spreading from the corporate network into production operations. Which action should the CISO prioritize to reduce lateral movement risk while still supporting business operations?

  1. A

    Place the manufacturing systems in a dedicated network segment with tightly defined firewall rules that allow only required communications to approved application servers and vendor endpoints

  2. B

    Deploy endpoint protection to the manufacturing systems and keep them on the same flat network as corporate users to avoid disrupting operations

  3. C

    Require all users to connect through the enterprise VPN before accessing the manufacturing systems, while leaving the manufacturing environment on the existing subnet

  4. D

    Increase internet perimeter filtering and web proxy restrictions for office users, because most ransomware initially enters through phishing

Show answer and explanation

Correct answer: A

Explanation

The best answer is to segment the manufacturing environment and strictly control allowed traffic. From a CCISO perspective, this reflects a governance-driven, risk-based control decision: when critical systems are operationally sensitive and difficult to patch, the organization should reduce exposure and limit blast radius through segmentation, least-privilege access, and restricted east-west traffic. This is consistent with widely accepted guidance such as NIST SP 800-41 on firewall policy, NIST SP 800-125/800-207 principles around isolation and trust boundaries, and ISA/IEC 62443 concepts for separating industrial environments into zones and conduits. While endpoint protection, VPN controls, and perimeter defenses all have value, they do not provide the same containment benefits as properly designed network segmentation for preventing lateral movement between corporate and operational environments.

  • A. Correct.

    Correct. Network segmentation is intended to limit unnecessary connectivity and contain compromise. Placing the manufacturing environment in a dedicated segment and enforcing least-privilege traffic flows through firewalls or ACLs directly addresses the board's concern about ransomware spreading laterally from the corporate network. This approach is especially appropriate for legacy or unpatchable systems because it reduces their exposure while preserving only the specific business-required communications.

  • B. Incorrect.

    Incorrect. Endpoint protection can be useful, but it does not replace segmentation. Keeping vulnerable manufacturing systems on a flat network preserves broad east-west connectivity, which increases the chance of lateral movement if either a user workstation or a production asset is compromised. The misconception is treating endpoint controls as sufficient compensation for weak network architecture.

  • C. Incorrect.

    Incorrect. VPN usage controls remote access, not internal trust boundaries. If the manufacturing systems remain on the same subnet or broadly reachable network, lateral movement risk inside the environment remains largely unchanged. This option confuses access authentication with segmentation and containment.

  • D. Incorrect.

    Incorrect. Better perimeter filtering may reduce some initial infection vectors, but it does not adequately address the stated risk of ransomware propagating from corporate systems into production operations after an internal compromise. The misconception is focusing only on ingress prevention rather than limiting blast radius through internal segmentation.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam