712-50 exam dumps

712-50 practice question 331 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 331

Single answerUnderstand system logs, patch management process and configuration management for information system security

A global manufacturing company discovers that a recently exploited vulnerability in a widely used web server affected several internet-facing systems. During the post-incident review, the CISO learns that some servers had the security patch applied, some were running unauthorized configuration changes, and log retention differed across business units, making it difficult to determine the attack timeline. The board asks for the single MOST effective governance action to reduce the likelihood and impact of similar failures in the future. Which action should the CISO prioritize?

  1. A

    Implement an enterprise-wide baseline configuration standard linked to formal change control, centralized log management with defined retention, and risk-based patch management with verification reporting

  2. B

    Require system administrators to apply critical patches immediately on all systems without exception and allow local teams to decide how long to keep logs based on storage availability

  3. C

    Outsource vulnerability scanning to a managed service provider and defer configuration standardization until all legacy systems are replaced

  4. D

    Increase the frequency of penetration tests and rely on incident response teams to identify unauthorized configuration changes during investigations

Show answer and explanation

Correct answer: A

Explanation

The best answer is Option 1 because the scenario shows systemic governance failures across three related security disciplines: system logging, patch management, and configuration management. An effective CISO response should not treat these as isolated technical problems. Instead, the organization needs an enterprise control framework that defines secure baselines, requires formal change approval and documentation, centralizes and standardizes logging, and operates a risk-based patch process with validation and reporting.

Relevant best practices support this integrated approach. NIST SP 800-40 Rev. 4 emphasizes enterprise patch management with prioritization, testing, deployment, and verification. NIST SP 800-92 highlights the need for centralized log management and consistent retention to support security operations and investigations. NIST SP 800-128 focuses on security-focused configuration management, including baselines and change control. CIS Controls also align strongly: inventory and control of enterprise assets, secure configuration of enterprise assets and software, continuous vulnerability management, audit log management, and change management.

From a CCISO viewpoint, the key is governance maturity: setting policy, assigning accountability, measuring compliance, and ensuring business units follow a common standard. The board asked for the MOST effective action to reduce both likelihood and impact. Option 1 directly improves prevention, detection, and forensic capability across the enterprise, making it the strongest strategic choice.

  • A. Correct.

    Correct. This option addresses the three control weaknesses revealed by the incident in an integrated way: configuration management, logging, and patch management. Establishing secure baseline configurations reduces drift and unauthorized changes; tying them to formal change control creates accountability and traceability. Centralized log management with defined retention improves visibility, correlation, and forensic readiness across business units. A risk-based patch management process with verification reporting ensures patches are prioritized, tested, deployed, and confirmed rather than assumed complete. From a CCISO perspective, this is the strongest governance-level response because it creates enterprise consistency and measurable oversight.

  • B. Incorrect.

    Incorrect. Although rapid patching of critical vulnerabilities is important, applying patches immediately on all systems without exception is not sound governance because it ignores testing, operational dependencies, and formal risk acceptance where patching is not immediately feasible. Allowing local teams to determine log retention based only on storage availability also weakens forensic capability, legal compliance, and incident response consistency. This option reflects a common misconception that speed alone is sufficient without control, validation, and standardization.

  • C. Incorrect.

    Incorrect. Vulnerability scanning is useful for identifying exposures, but it does not replace a mature patch management or configuration management program. Deferring configuration standardization until legacy replacement leaves the organization exposed in the meantime and fails to address current control gaps. This option is plausible because organizations often rely too heavily on scanning, but scanning detects issues; it does not enforce authorized configurations or ensure remediation governance.

  • D. Incorrect.

    Incorrect. More frequent penetration testing can help identify exploitable weaknesses, but it is a detective activity, not a primary control for maintaining secure configurations or ensuring timely patching. Relying on incident response teams to discover unauthorized changes after an event is reactive and costly. This option confuses assurance activities with foundational operational controls. The issue described requires preventive and governance-based controls, not merely additional testing.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam