712-50 exam dumps

712-50 practice question 329 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 329

Single answerIdentify various OS vulnerabilities and attacks and develop a plan for hardening OS systems

A global manufacturing company is integrating a recently acquired business unit. During due diligence, the CISO learns that several Linux and Windows servers in the acquired environment still permit legacy remote administration methods, expose unnecessary services, and are inconsistently patched because operations teams fear downtime in production. A recent incident involved attackers gaining an initial foothold through an exposed service account and then moving laterally using remote management protocols. The board has asked for a practical OS hardening plan that reduces attack surface quickly while balancing operational continuity. Which action should the CISO prioritize FIRST to most effectively reduce risk across the mixed-server environment?

  1. A

    Establish a risk-based OS hardening baseline that disables unnecessary services and legacy protocols, enforces secure configuration standards, and integrates staged patching with change management

  2. B

    Purchase a new endpoint detection and response platform and defer OS configuration changes until all production teams approve a long-term transformation roadmap

  3. C

    Mandate immediate full patching of every server in a single maintenance window, regardless of business criticality, to eliminate all known vulnerabilities at once

  4. D

    Rely on network firewall rule tightening to protect the servers while leaving local services, administrative protocols, and default configurations unchanged

Show answer and explanation

Correct answer: A

Explanation

The best answer is to prioritize a risk-based OS hardening baseline combined with staged patching and change management. In real enterprises, especially after acquisitions, inconsistent configurations, legacy protocols, unnecessary services, weak account practices, and delayed patching create a broad attack surface. Effective OS hardening begins with secure baselines, asset inventory, service rationalization, protocol restriction, least privilege, and patch governance. This aligns with established best practices from CIS Benchmarks, DISA STIGs, Microsoft Security Baselines, NIST SP 800-123 (Guide to General Server Security), and NIST SP 800-40 on enterprise patch management. From a CCISO perspective, the key is not merely knowing technical controls, but selecting the sequence of actions that yields measurable risk reduction while preserving business operations. Hardening baselines reduce exposure immediately and create the structure needed for sustainable patching, monitoring, exception handling, and auditability.

  • A. Correct.

    Correct. This is the most effective first priority because it addresses multiple root causes of OS compromise in a practical, governance-aligned manner: reducing attack surface by disabling unnecessary services, removing or restricting legacy/insecure protocols, standardizing secure configurations, and implementing a staged patching approach through formal change management. In a mixed Windows/Linux environment, hardening baselines aligned to recognized standards such as CIS Benchmarks, DISA STIGs, Microsoft Security Baselines, and vendor guidance provide immediate and sustainable risk reduction. This approach is especially appropriate for a CISO because it balances security improvement with operational continuity rather than focusing narrowly on a single tool or a disruptive one-time action.

  • B. Incorrect.

    Incorrect. EDR can improve detection and response, but it does not replace foundational OS hardening. The scenario specifically highlights exposed services, legacy remote administration, and inconsistent patching. Deferring configuration changes prolongs exposure to preventable weaknesses. A common misconception is that advanced security tooling can compensate for weak baseline system security; in practice, hardening and least functionality remain core controls, with EDR serving as a complementary detective capability.

  • C. Incorrect.

    Incorrect. Although patching is important, an immediate blanket patching mandate across all systems without prioritization, testing, or change management is not the best first step for a CISO in a production environment. It may create operational outages and resistance from business units, undermining the program. The scenario calls for a practical plan balancing risk reduction and continuity. A risk-based baseline with staged remediation is more realistic and sustainable. The misconception here is equating urgency with indiscriminate action rather than controlled, risk-informed execution.

  • D. Incorrect.

    Incorrect. Network firewalls are important compensating controls, but they do not address vulnerabilities caused by insecure local configurations, unnecessary services, weak service account usage, or permissive remote administration within the internal network. Since the attackers already moved laterally using remote management protocols, leaving host-level configurations unchanged would preserve major attack paths. This option reflects a perimeter-focused mindset that is insufficient against modern lateral movement and internal compromise.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam