712-50 exam dumps

712-50 practice question 342 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 342

Single answerDesign, develop and implement a penetration testing program based on penetration testing methodology to ensure organizational security

A newly appointed CISO is formalizing an enterprise penetration testing program after a customer audit found that prior testing was ad hoc, focused almost entirely on external network scans, and repeatedly caused service disruptions in production. The organization now operates on-premises systems, cloud-hosted customer applications, and several critical third-party integrations. Executive leadership wants a program that provides meaningful assurance without creating unacceptable operational risk. Which action should the CISO take FIRST to design and implement a sustainable penetration testing program aligned to recognized methodology?

  1. A

    Establish a risk-based penetration testing standard that defines scope, rules of engagement, testing frequency, target prioritization, authorization, and retesting requirements before scheduling new tests

  2. B

    Require all business units to perform quarterly full-scope black-box penetration tests against production systems to create a consistent enterprise baseline

  3. C

    Procure the most advanced automated exploitation platform available and use it as the primary mechanism for testing internal, external, and cloud environments

  4. D

    Begin with red team exercises against critical assets to simulate realistic attackers, then develop governance and reporting standards after leadership reviews the initial results

Show answer and explanation

Correct answer: A

Explanation

The best first step is to create a formal, risk-based penetration testing standard and operating model. Effective programs are built on recognized methodology and governance, including planning and preparation, scope definition, rules of engagement, legal authorization, communication and escalation paths, testing constraints, evidence handling, reporting, remediation tracking, and retesting. This is consistent with industry practices reflected in NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment), PTES (Penetration Testing Execution Standard), and OWASP testing guidance for application-focused assessments. From a CCISO perspective, the emphasis is on establishing enterprise oversight, aligning testing to business risk, reducing operational disruption, and ensuring results drive remediation and measurable security improvement. Once the standard exists, the CISO can select appropriate test types, frequencies, providers, and tooling for different environments such as external infrastructure, internal networks, cloud workloads, applications, and third-party dependencies.

  • A. Correct.

    Correct. A sustainable penetration testing program begins with governance and methodology, not tooling or isolated test execution. A risk-based standard should define objectives, in-scope assets, test types, rules of engagement, required approvals, data handling, communication paths, blackout windows, production safeguards, severity/risk rating approach, reporting expectations, and remediation validation. This addresses the organization's current problems: inconsistent scope, overemphasis on external scanning, and operational disruption. It also aligns with common penetration testing methodology phases such as planning, scoping, reconnaissance, exploitation, post-exploitation limits, reporting, and retesting.

  • B. Incorrect.

    Incorrect. Quarterly testing may be appropriate for some high-risk assets, but mandating full-scope black-box tests for all business units and production systems is not risk-based and could increase service disruption. It also ignores different testing approaches that may be more appropriate depending on system criticality, architecture, data sensitivity, and operational constraints. A mature program tailors frequency and depth to risk and business impact rather than imposing a uniform cadence everywhere.

  • C. Incorrect.

    Incorrect. Automation can support vulnerability discovery and validation, but penetration testing is not primarily a tool procurement exercise. Automated exploitation platforms do not replace program governance, scoping, rules of engagement, manual validation, or business-context-driven prioritization. Relying on a tool first is a common misconception that confuses vulnerability scanning or automated attack simulation with a controlled penetration testing program.

  • D. Incorrect.

    Incorrect. Red teaming can be valuable, but it is a higher-maturity activity designed to emulate realistic adversaries and test detection and response, not the first step for building core penetration testing governance. Starting with red team exercises before defining scope, authorization, reporting, and operational controls would likely repeat the organization's previous problem of disruptive, inconsistent testing. Governance should precede advanced exercises.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam