712-50 exam dumps

712-50 practice question 334 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 334

Single answer

A newly appointed CISO is reviewing how a global enterprise protects sensitive merger documents exchanged with an external law firm. The board requires that the documents remain unreadable if intercepted, that recipients can verify the sender's identity, and that controls scale across multiple business units without manually managing trust for each partner. During the review, a senior manager suggests embedding the files inside image attachments because 'that encrypts the content and removes the need for certificates.' Which approach should the CISO recommend?

  1. A

    Use steganography to hide the merger documents inside image files because concealment provides confidentiality and sender authentication without additional infrastructure.

  2. B

    Use symmetric encryption only with a shared password communicated by phone, because encryption alone provides confidentiality, nonrepudiation, and scalable trust between organizations.

  3. C

    Use a PKI-based solution in which the sender encrypts the documents for the law firm using the recipient's public key and signs them with the sender's private key, with digital certificates validating identities.

  4. D

    Use digital certificates only to identify users, but send the merger documents in plaintext because certificate-based identity makes encryption unnecessary once trust is established.

Show answer and explanation

Correct answer: C

Explanation

The best answer is the PKI-based approach because it combines core cryptographic functions with scalable trust management. In a real enterprise scenario, the CISO must align controls to business requirements: confidentiality is achieved through encryption, identity assurance and integrity are supported through digital signatures, and scalable inter-organizational trust is enabled through PKI and digital certificates. Public key cryptography allows a sender to encrypt data using a recipient's public key so only the holder of the corresponding private key can decrypt it. Likewise, a sender can digitally sign data with their private key, and recipients can verify the signature with the sender's public key.

The manager's suggestion incorrectly conflates steganography with cryptography. Cryptography transforms data to make it unreadable without the proper key, while steganography attempts to hide the existence of the message itself. Steganography does not inherently provide confidentiality, integrity, authentication, or nonrepudiation. In practice, if steganography is used at all, it is typically supplementary rather than a replacement for encryption.

This recommendation is consistent with widely accepted security principles described in NIST guidance on cryptographic key management and public key infrastructures, as well as industry best practices for secure electronic communications. PKI supports lifecycle management for certificates, revocation checking, trust chains, and identity validation, all of which are important at the executive governance level when dealing with sensitive, cross-organizational exchanges.

  • A. Incorrect.

    Incorrect. Steganography hides the existence of data but does not inherently encrypt it, authenticate the sender, or establish scalable trust. If the hidden content is discovered, it may still be readable unless separately encrypted. This option reflects a common misconception that concealment is equivalent to cryptographic protection. In enterprise communications, steganography is not a substitute for encryption, digital signatures, or certificate-based trust management.

  • B. Incorrect.

    Incorrect. Symmetric encryption can provide confidentiality, but by itself it does not provide nonrepudiation because both parties share the same secret key. It also does not scale well across many external partners, since secure key distribution and trust establishment become operationally difficult. Communicating a password by phone may be used as an out-of-band mechanism in limited cases, but it is not an enterprise-scale replacement for PKI and certificates.

  • C. Correct.

    Correct. This approach addresses all business requirements. Encrypting with the recipient's public key protects confidentiality because only the recipient's private key can decrypt the content. Signing with the sender's private key supports authentication, integrity, and nonrepudiation, assuming private key control is maintained. Digital certificates, issued and managed under a PKI, bind public keys to verified identities and allow trust to scale across business units and external partners through certificate validation processes.

  • D. Incorrect.

    Incorrect. Digital certificates do not replace encryption; they support trust by binding identities to public keys. Sending merger documents in plaintext would leave them exposed if intercepted. This option confuses identity assurance with confidentiality. Trust in identity is valuable, but sensitive content still requires cryptographic protection during transmission or storage.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam