712-50 exam dumps

712-50 practice question 310 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 310

Single answer

A global software company has experienced two malware-related incidents in one quarter: a Trojan was introduced through a developer's compromised third-party package dependency, and ransomware spread from a finance employee's phishing email attachment to a shared file server. The CEO asks the CISO to present one initiative that most effectively addresses both security teams and non-security teams while reducing malware risk across the software lifecycle and day-to-day business operations. Which action should the CISO prioritize?

  1. A

    Launch an organization-wide secure development and malware awareness program that includes role-based training for developers on dependency hygiene, code signing, and build pipeline controls, and training for non-technical staff on phishing, unsafe attachments, and reporting procedures

  2. B

    Require the security operations team to perform weekly full malware scans on all endpoints and servers, while keeping existing developer and employee training unchanged

  3. C

    Block all email attachments at the gateway and prohibit developers from using any external open-source libraries in production applications

  4. D

    Invest primarily in a new perimeter firewall with advanced malware signatures, because most malware enters through the network edge rather than through user actions or software dependencies

Show answer and explanation

Correct answer: A

Explanation

The best answer is the role-based secure development and malware awareness initiative because it directly addresses the two infection vectors in the scenario: third-party dependency compromise and phishing-delivered ransomware. CCISO-level decision-making requires selecting a control strategy that is risk-based, scalable, and aligned to business operations. Malware enters organizations through multiple mediums, including email attachments, malicious links, removable media, compromised websites, unpatched systems, and increasingly through software supply chains such as tampered packages, build environments, and libraries. A CISO should therefore implement layered controls, but when asked to prioritize one initiative that helps both security and non-security teams, role-based education tied to secure processes is the strongest answer.

This approach aligns with widely accepted practices from NIST SP 800-61 on incident handling, NIST Secure Software Development Framework (SP 800-218), and general guidance from NIST Cybersecurity Framework and OWASP Software Supply Chain Security principles. For developers, secure development processes should include dependency governance, provenance verification, code review, signing, and CI/CD hardening. For non-security teams, phishing awareness, attachment handling, macro restrictions, and clear reporting paths reduce the likelihood and impact of malware infections. The key leadership insight is that malware defense is not solely a SOC problem; it requires coordinated security processes across development, operations, and business users.

  • A. Correct.

    Correct. This option addresses both infection sources described in the scenario: software supply chain risk affecting developers and phishing-based malware affecting non-security staff. A role-based program is aligned with secure development best practices and enterprise awareness expectations. For developers, training should cover trusted repositories, software composition analysis, package integrity verification, least-privilege build systems, code signing, and CI/CD security controls. For business users, phishing recognition, attachment handling, macro risks, and prompt reporting are essential. This approach reduces the likelihood of malware introduction through both technical and human channels and supports a sustainable security culture rather than a one-time technical fix.

  • B. Incorrect.

    Incorrect. Malware scanning is useful as a detective and sometimes preventive control, but it does not adequately address the root causes in the scenario. Weekly scans may miss fast-moving attacks, and unchanged training leaves developers vulnerable to poisoned dependencies and employees vulnerable to phishing. This option over-relies on operational security tooling while neglecting the people and process improvements needed to reduce malware introduction.

  • C. Incorrect.

    Incorrect. This option is overly restrictive and operationally impractical. Blocking all attachments may disrupt legitimate business processes, and banning all open-source libraries is not realistic for most modern software organizations. The better practice is governed use of open-source components with validation, inventory, patching, and provenance checks. Similarly, email controls should be risk-based and layered rather than absolute. This distractor reflects a common misconception that elimination through blanket prohibition is the most effective governance response.

  • D. Incorrect.

    Incorrect. Firewalls and network-based malware detection are important, but the scenario specifically highlights two common malware entry mediums that often bypass simple perimeter assumptions: phishing attachments acted on by users and compromised software dependencies introduced during development. Modern malware risk frequently involves endpoints, identity, applications, cloud services, and supply chain paths, not just the traditional network edge. Prioritizing only perimeter controls would leave major exposure unaddressed.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam