712-50 exam dumps

712-50 practice question 340 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 340

Single answerVulnerability Assessment and Penetration Testing (5 questions)

A global financial services company is preparing for its annual security assessment cycle. The CISO learns that business units have been independently running authenticated vulnerability scans in production, while the internal red team is planning an external penetration test against internet-facing applications. Last year, several critical findings remained unresolved because results from different activities were mixed together and reported without business context. To improve governance and decision-making, which action should the CISO take FIRST to ensure vulnerability assessment and penetration testing provide clear, actionable risk information to executives and system owners?

  1. A

    Require all testing teams to use the same scanning tool so results can be consolidated into a single dashboard

  2. B

    Establish a formal assessment strategy that defines the objective, scope, rules of engagement, methodology, and reporting requirements separately for vulnerability assessments and penetration tests

  3. C

    Delay penetration testing until all vulnerabilities identified by automated scanners have been remediated

  4. D

    Outsource both vulnerability scanning and penetration testing to an external provider to eliminate internal inconsistency

Show answer and explanation

Correct answer: B

Explanation

The best first step is to create a formal, risk-based assessment strategy that distinguishes vulnerability assessment from penetration testing and defines how each supports business objectives. Vulnerability assessments are typically broader, focused on identifying known weaknesses through automated and manual review, while penetration tests are goal-oriented exercises that validate exploitability and demonstrate business impact. At the executive level, the CISO must ensure these activities are governed with clear scope, authorization, frequency, rules of engagement, and reporting standards so that findings can be prioritized and remediated effectively.

This approach aligns with widely accepted practices such as NIST SP 800-115, which differentiates security testing techniques and emphasizes planning, rules of engagement, and reporting, as well as the PTES and industry-standard vulnerability management programs that separate identification of weaknesses from exploitation-based validation. For a CCISO candidate, the key point is governance: leadership must ensure assessments produce decision-useful, risk-contextualized outputs rather than raw technical data.

  • A. Incorrect.

    Using the same scanning tool may improve consistency in vulnerability data collection, but it does not solve the core governance problem. Vulnerability assessments and penetration tests have different purposes, methods, outputs, and levels of validation. A single dashboard without clear distinctions can further blur the difference between identified weaknesses and successfully exploited attack paths.

  • B. Correct.

    This is correct because the primary issue is lack of governance and clarity around testing objectives and outputs. A formal strategy should distinguish vulnerability assessments from penetration tests, define scope and authorization, set rules of engagement for production systems, specify acceptable methodologies, and require reporting that maps technical findings to business risk and remediation ownership. This allows executives to understand whether a finding is an unverified weakness, a validated exploit path, or a systemic control failure.

  • C. Incorrect.

    This is incorrect because penetration testing should not automatically be delayed until all scanner findings are fixed. Penetration testing is used to simulate realistic attack scenarios, validate exploitability, and identify chained weaknesses and control gaps that scanners alone may not reveal. In many organizations, risk-based penetration testing is valuable even when known vulnerabilities still exist.

  • D. Incorrect.

    Outsourcing may provide specialized expertise, but it does not inherently resolve unclear objectives, poor scoping, or inconsistent reporting. Without an internal governance framework, an external provider may produce technically sound reports that still fail to meet executive decision-making needs. Accountability for assessment strategy remains with organizational leadership.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam