712-50 exam dumps

712-50 practice question 339 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 339

Single answerDevelop a plan for information security encryption techniques

A newly appointed CISO is creating an enterprise encryption plan for a global company that processes payment card data, stores customer PII in multiple regions, and operates a mix of on-premises systems and cloud-native applications. Recent internal audits found inconsistent use of encryption, locally stored application keys, and no formal process for cryptographic algorithm review. The board has asked for a plan that reduces business risk, supports regulatory obligations, and remains maintainable over time. Which action should the CISO prioritize FIRST to build an effective encryption strategy?

  1. A

    Define a data classification and cryptographic governance standard that maps data sensitivity, regulatory requirements, approved algorithms, key ownership, and lifecycle controls before selecting specific technical implementations

  2. B

    Mandate full-disk encryption across all servers and endpoints immediately, because this provides uniform protection regardless of data type or business process

  3. C

    Require each application team to choose its own encryption libraries and key storage approach, since local ownership increases delivery speed and aligns security to application needs

  4. D

    Standardize on a single encryption algorithm and key length for every use case, so the organization can simplify procurement, training, and operations

Show answer and explanation

Correct answer: A

Explanation

The scenario is asking for the first strategic step in developing an enterprise encryption plan, not the first tactical control to deploy. In CCISO practice, the CISO should begin by establishing governance: understanding data types, business processes, legal and regulatory requirements, and then defining cryptographic standards and key management responsibilities. This approach enables risk-based prioritization and supports maintainability over time. Widely accepted guidance supports this sequence. NIST guidance on key management and cryptographic use, such as NIST SP 800-57 and NIST SP 800-175B, emphasizes selecting cryptographic protections based on data sensitivity, use case, and lifecycle requirements. PCI DSS requires strong cryptography and key management for payment card data, but implementation must be tied to where account data is stored, processed, and transmitted. ISO/IEC 27001 and 27002 also support policy-driven, risk-based selection of cryptographic controls. Therefore, the best first action is to define a formal enterprise cryptographic governance model tied to data classification and key lifecycle management, then implement the appropriate technical controls consistently across the environment.

  • A. Correct.

    Correct. At the executive level, an effective encryption plan starts with governance and alignment to business and regulatory requirements. The CISO should first establish a data classification model and cryptographic standard that defines what must be encrypted, where encryption is required (data at rest, in transit, and where applicable in use), which algorithms and modes are approved, how keys are generated, stored, rotated, escrowed, retired, and who owns decisions. This creates consistency across on-premises and cloud environments and prevents the fragmented control failures described in the scenario.

  • B. Incorrect.

    Incorrect. Full-disk encryption is useful, especially for lost or stolen devices and some server scenarios, but it does not address all business requirements. It does not replace application-level, database-level, field-level, or transport encryption where those are needed. Prioritizing it first without governance can leave gaps in key management, data flow coverage, and regulatory mapping.

  • C. Incorrect.

    Incorrect. Allowing each application team to independently choose encryption methods and key management approaches usually increases risk, inconsistency, and audit findings. It can lead to weak or unsupported libraries, poor key storage practices, and noncompliance. While development teams need implementation flexibility, the encryption strategy should be centrally governed with approved standards and architectural guardrails.

  • D. Incorrect.

    Incorrect. A single algorithm and key length for every use case is not an effective enterprise strategy. Different use cases require different cryptographic approaches, such as symmetric encryption for bulk data, asymmetric cryptography for key exchange or digital signatures, hashing for integrity, and tokenization in some data protection scenarios. Standardization is important, but oversimplification can create operational and security problems.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam