712-50 exam dumps

712-50 practice question 311 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 311

Select 2

A CISO is reviewing a surge in malware-related incidents after the organization accelerated software delivery using a cloud-based CI/CD pipeline. Investigation shows that one development team downloaded an unverified open-source build tool from a public repository, while several business users installed browser extensions from unofficial sites to improve productivity. The board asks for a response that both reduces the risk of virus, Trojan, and malware infection across the enterprise and improves secure development practices for security and non-security teams. Which TWO actions should the CISO prioritize first?

  1. A

    Establish an approved software acquisition and dependency governance process that requires vetted package sources, integrity verification, and code signing validation for developer tools and third-party components

  2. B

    Limit malware awareness training to the security operations team because developers and business users are not primary responders to malware incidents

  3. C

    Implement role-based secure development and malware awareness training for developers, IT administrators, and business users, including risks from phishing, malicious browser extensions, macros, and poisoned software packages

  4. D

    Rely primarily on endpoint antivirus signatures and remove manual review of software sources to avoid slowing delivery pipelines

  5. E

    Permit teams to download tools directly from the Internet as long as they scan files after installation

Show answer and explanation

Correct answers: A, C

Explanation

The best answer is to prioritize controls that address the most likely infection mediums shown in the scenario while also improving secure development practices organization-wide. Modern malware enters organizations through multiple channels, including phishing, malicious macros, browser extensions, removable media, drive-by downloads, untrusted installers, and increasingly through software supply chain compromise involving open-source packages, build tools, and third-party libraries. For a CISO, the most effective first steps are: (1) establish governance over software acquisition and dependencies so that developer tools and packages come from trusted, validated sources; and (2) provide role-based awareness and secure development training to both security and non-security teams. This aligns with widely accepted practices in NIST SP 800-53 supply chain and awareness controls, NIST Secure Software Development Framework (SSDF), and CIS Controls relating to application control, secure configuration, malware defenses, and security awareness. The key leadership principle is that malware risk is an enterprise issue, not just a SOC issue, and secure development must be supported by both technical controls and human behavior change.

  • A. Correct.

    This is correct because a major malware infection vector in modern environments is the software supply chain: untrusted packages, tampered installers, typo-squatted dependencies, and compromised repositories. A governance process for approved repositories, software allowlisting, integrity checks (such as hashes), and code-signing validation materially reduces the risk of Trojans and malware entering developer workstations and build pipelines. This is especially important in CI/CD environments where a single compromised tool can propagate malware into multiple systems or releases.

  • B. Incorrect.

    This is incorrect because malware prevention is not solely the responsibility of security operations. Developers, administrators, and business users all influence malware exposure through actions such as downloading tools, enabling macros, installing extensions, and handling email attachments. Limiting training to the security team ignores common infection sources and weakens organizational resilience. A CCISO should promote shared responsibility and targeted education across technical and non-technical functions.

  • C. Correct.

    This is correct because the scenario involves both technical and non-technical infection paths: unverified developer tools, unofficial browser extensions, and likely phishing or social engineering vectors. Role-based training helps each audience understand the threats relevant to them and supports secure development processes. Developers should be trained on secure dependency management and trusted build practices; administrators on hardening and privileged access risks; and business users on malicious attachments, links, extensions, and removable media. This addresses both prevention and organizational behavior.

  • D. Incorrect.

    This is incorrect because antivirus signatures alone are insufficient against modern malware, especially fileless malware, zero-day threats, malicious scripts, and supply chain compromises. Removing source review would increase risk by allowing untrusted software into the environment unchecked. Defense-in-depth requires preventive, detective, and governance controls, not just signature-based endpoint protection.

  • E. Incorrect.

    This is incorrect because scanning after installation is too late as a primary control. Malware may execute during installation, establish persistence, or evade detection. Allowing unrestricted downloads from the Internet undermines secure development and enterprise malware controls. Prevention should focus on trusted sources, least privilege, application control, and validation before installation or execution.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam