712-50 exam dumps

712-50 practice question 341 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 341

Single answerVulnerability Assessment and Penetration Testing (5 questions)

A newly appointed CISO is reviewing the organization's vulnerability assessment and penetration testing program after a recent external audit found that quarterly vulnerability scans were completed on schedule, yet a red-team exercise successfully exploited an internet-facing application through a flaw introduced during a recent code release. Development leaders argue that the existing scanning program is sufficient because it already produces remediation tickets. The board has asked the CISO for the single BEST improvement to reduce the likelihood of similar findings in the future while maintaining business agility. What should the CISO prioritize?

  1. A

    Increase the frequency of enterprise vulnerability scans from quarterly to monthly for all assets

  2. B

    Integrate application-specific security testing into the software delivery lifecycle and supplement scanning with targeted penetration testing for high-risk changes

  3. C

    Require the infrastructure team to remediate all scanner findings before any new application release is approved

  4. D

    Replace vulnerability scanning with annual third-party penetration tests because real attackers use exploitation techniques rather than scanners

Show answer and explanation

Correct answer: B

Explanation

The scenario highlights an important executive-level distinction: vulnerability assessment and penetration testing serve different purposes and should be managed as complementary components of a risk-based assurance program. Vulnerability scanning is effective for broad identification of known technical weaknesses and misconfigurations, but it is not sufficient to uncover all application-layer and release-specific risks. A flaw introduced during a recent code release suggests a weakness in change assurance, secure SDLC integration, or risk-based validation of critical applications.

From a CCISO perspective, the best improvement is to embed security testing into the development and release process and use targeted penetration testing for high-risk systems or significant changes. This aligns with widely accepted practices from NIST SP 800-115 on technical security testing, the OWASP guidance on integrating security into the SDLC, and risk-based testing principles reflected in governance frameworks such as NIST CSF and ISO/IEC 27001/27002. The goal is not simply to do more scanning, but to improve control coverage where the risk actually emerges: during application change and deployment.

Executive leadership should ensure the program distinguishes between breadth-oriented activities like vulnerability assessments and depth-oriented validation such as penetration testing, then align both to asset criticality, threat exposure, and release cadence.

  • A. Incorrect.

    Increasing scan frequency may improve timeliness for identifying known vulnerabilities, but it does not directly address the core issue in the scenario: a flaw introduced during a recent code release in an internet-facing application. Traditional enterprise vulnerability scans often miss business logic issues, authentication flaws, insecure coding patterns, and release-specific weaknesses. This option reflects a common misconception that more frequent scanning alone can compensate for limited testing depth.

  • B. Correct.

    This is the best answer because it addresses the process gap that allowed a release-introduced flaw to reach production. Integrating security testing into the SDLC, such as SAST, DAST, software composition analysis, and risk-based manual testing where appropriate, helps detect weaknesses earlier and closer to deployment. Adding targeted penetration testing for high-risk applications or major changes provides validation of exploitability and attack paths that scanners may not identify. This approach improves coverage while preserving agility through risk-based testing rather than relying only on periodic enterprise scans.

  • C. Incorrect.

    This option is too broad and operationally unrealistic. Not all scanner findings have equal risk, and blocking releases until all findings are remediated can create unnecessary delays without materially reducing the most significant application security risks. A mature program prioritizes remediation based on criticality, exploitability, asset value, exposure, and compensating controls. Also, infrastructure findings are not the same as application-layer release defects, which were the root issue in the scenario.

  • D. Incorrect.

    This option creates a false choice. Penetration testing and vulnerability scanning are complementary, not interchangeable. Replacing scanning with annual tests would reduce continuous visibility into known vulnerabilities and misconfigurations across the environment. Annual testing alone is insufficient for dynamic environments with frequent releases. Best practice is to use layered assurance: continuous or periodic scanning, secure development controls, and targeted penetration testing based on risk.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam