712-50 exam dumps

712-50 practice question 323 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 323

Single answerInstall and operate the IT systems in a test configuration manner that does not alter the program code or compromise security safeguards

A CISO is overseeing pre-production validation of a new payment processing platform that must be installed and operated in a test configuration before go-live. The application owner wants the team to speed up testing by disabling endpoint protection on the servers, using production customer data to ensure realism, and applying small code changes to bypass multifactor authentication during scripted test runs. The CISO must approve an approach that allows meaningful testing without altering program code or weakening security safeguards. Which action is the BEST choice?

  1. A

    Build an isolated test environment that mirrors production security controls, use sanitized or tokenized data, and execute testing through configuration management and test accounts rather than changing application code

  2. B

    Allow temporary code modifications to bypass multifactor authentication, provided the changes are documented and removed before production deployment

  3. C

    Use production data in the test environment under a non-disclosure agreement, since contractual controls are sufficient to offset the risk

  4. D

    Disable selected security agents during testing to reduce false positives, then re-enable them after test completion and include the exception in the risk register

Show answer and explanation

Correct answer: A

Explanation

The best answer is Option 1 because it aligns with secure system testing principles: preserve code integrity, maintain security controls, and use representative but non-sensitive test data. From a leadership and governance perspective, a CISO should require testing approaches that produce reliable results without introducing new risk. This includes environment isolation, configuration-based testing, least-privilege test accounts, logging, and data protection measures such as masking or tokenization. These practices are consistent with widely accepted guidance in NIST SP 800-115 on security testing, NIST SP 800-53 controls related to test, development, and security configuration, and general secure SDLC and change management practices. In short, effective testing should emulate production conditions as closely as possible while avoiding code modifications and avoiding any reduction in baseline security safeguards.

  • A. Correct.

    This is correct because it preserves the integrity of the application code while maintaining security safeguards in the test environment. An isolated environment that closely mirrors production is a core testing best practice because it increases the validity of results without exposing production systems. Using sanitized, masked, or tokenized data reduces privacy and regulatory risk compared with using live customer records. Conducting tests through configuration, role-based test accounts, and approved test procedures avoids introducing code-level deviations that could invalidate results or create unmanaged security weaknesses.

  • B. Incorrect.

    This is incorrect because altering program code to bypass security controls directly conflicts with the requirement to test without changing code or compromising safeguards. Even if documented, temporary code changes can invalidate test results, create version control issues, and introduce the risk that insecure logic persists into later builds. A common misconception is that documentation alone makes such changes acceptable; in reality, secure testing should rely on approved configurations, test identities, and environment controls rather than code bypasses.

  • C. Incorrect.

    This is incorrect because legal agreements do not eliminate the technical, privacy, and compliance risks of exposing production data in a test environment. Real customer data should generally not be used unless there is a formally justified exception with strong controls, and even then it is not the preferred approach. The better practice is to use masked, synthetic, or tokenized data. This option reflects the common but flawed assumption that administrative controls can fully compensate for weaker technical safeguards.

  • D. Incorrect.

    This is incorrect because disabling endpoint protection or other security safeguards undermines the requirement to operate the system in a secure test configuration. Although test teams sometimes view security tools as obstacles, removing them can hide operational issues that would appear in production and can expose the environment to avoidable threats. Proper tuning, allowlisting, or test-specific policy configuration is preferable to disabling protective controls.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam