712-50 exam dumps

712-50 practice question 344 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 344

Single answerIdentify different vulnerabilities associated with information systems and legal issues involved in penetration testing

A newly appointed CISO authorizes an external firm to perform a penetration test against the company's internet-facing applications. The company uses a cloud-hosted customer portal that integrates with a third-party payment processor and also shares infrastructure with a recently acquired subsidiary. During planning, the testing firm proposes broad reconnaissance and exploitation of any reachable targets from the public IP ranges. Which action should the CISO take FIRST to best reduce legal and operational risk while still enabling an effective assessment?

  1. A

    Approve the test immediately because internet-facing assets are implicitly in scope for security testing

  2. B

    Require a signed rules-of-engagement document that explicitly defines scope, authorization, excluded assets, testing windows, third-party approvals, and points of contact before any testing begins

  3. C

    Instruct the testing firm to avoid denial-of-service techniques but otherwise allow unrestricted exploitation of all discovered systems

  4. D

    Rely on the master services agreement with the testing firm because it already establishes a business relationship and general confidentiality terms

Show answer and explanation

Correct answer: B

Explanation

The best first action is to establish explicit written authorization and a detailed rules-of-engagement document before testing starts. From a CCISO perspective, this is a governance, risk, and legal control issue as much as a technical one. In this scenario, several vulnerabilities and legal exposures intersect: internet-facing systems are likely to contain common technical weaknesses such as unpatched software, misconfigurations, weak authentication, exposed administrative interfaces, insecure APIs, and overly permissive network paths; however, identifying those vulnerabilities through penetration testing must be bounded by lawful authority.

Because the customer portal is cloud-hosted, integrated with a third-party payment processor, and shares infrastructure with an acquired subsidiary, the company may not have unilateral authority to test every reachable asset in the public IP range. Testing beyond owned or expressly authorized systems could violate contracts, acceptable use terms, data protection obligations, or even computer misuse laws in some jurisdictions. This is why mature penetration testing programs require, at minimum, a signed authorization letter, rules of engagement, defined scope, asset inventory, testing windows, emergency contacts, and written approval from any affected third parties.

This aligns with established best practices from sources such as NIST SP 800-115, which emphasizes planning, scope definition, and rules of engagement for technical security testing, and with PTES guidance on pre-engagement interactions. In practice, the CISO should ensure that ownership of all targets is verified, cloud and processor approvals are obtained where required, sensitive production constraints are documented, and incident response and legal teams are informed before testing begins.

  • A. Incorrect.

    This is incorrect because public exposure does not create legal authority to test. Internet-facing systems may include assets owned or managed by third parties, shared environments, or systems outside the intended scope. Proceeding without explicit authorization and boundaries creates significant legal, contractual, and operational risk.

  • B. Correct.

    This is correct because a formal rules-of-engagement and written authorization are foundational controls for lawful and well-governed penetration testing. The scenario includes cloud services, a third-party payment processor, and shared infrastructure from an acquisition, all of which raise scope and ownership concerns. Explicit scope definition, exclusions, timing, escalation paths, and third-party permissions help prevent unauthorized testing, service disruption, and contractual violations.

  • C. Incorrect.

    This is incorrect because limiting only denial-of-service activity does not address the core legal issue: whether the tester is authorized to probe and exploit each target. Unrestricted exploitation across all reachable systems can impact third-party environments, shared tenants, or regulated systems and may exceed what the organization is entitled to authorize.

  • D. Incorrect.

    This is incorrect because a master services agreement typically governs commercial terms and confidentiality, but it is not a substitute for explicit test authorization and detailed engagement parameters. Without a specific authorization letter and rules of engagement, the testers may still lack documented permission for particular assets, methods, timeframes, and third-party systems.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam