712-50 Question 346
Single answerDevelop pre and post testing proceduresA global financial services company is preparing for an external penetration test of its internet-facing applications and supporting infrastructure. The CIO is concerned that prior tests created operational disruption and produced findings that were difficult to validate afterward. As the CISO, you are updating the organization's pre-test and post-test procedures to improve control, evidence quality, and business resilience. Which action should be included as the MOST effective improvement to the formal testing procedure?
- A
Require a pre-test checklist that confirms scope, rules of engagement, test windows, emergency contacts, backup validation, logging/monitoring readiness, and explicit success criteria for post-test verification.
- B
Allow the testing team to begin once the statement of work is signed, because detailed operational coordination can be handled dynamically during the engagement.
- C
Focus pre-test preparation on obtaining executive approval and defer backup checks and monitoring validation until after the test to avoid delaying the engagement.
- D
Limit post-test activities to receiving the final report from the tester, since remediation planning should begin only after all technical details are reviewed by system owners.
Show answer and explanation
Correct answer: A
Explanation
For CCISO-level leadership, developing pre-test and post-test procedures is primarily a governance, risk, and operational resilience activity rather than only a technical testing task. Effective pre-test procedures typically include authorization, defined scope, rules of engagement, communication channels, emergency stop procedures, asset criticality review, restoration readiness, and monitoring/logging preparation. Effective post-test procedures include confirming system stability, preserving evidence, validating findings, documenting exceptions, conducting lessons learned, and assigning remediation ownership. These practices align with broadly accepted security testing and governance principles found in sources such as NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment), NIST SP 800-61 for incident handling coordination considerations, and general control expectations from audit and risk management frameworks. The best answer is the one that integrates both pre-test controls and post-test validation into a formal, repeatable procedure.
- A. Correct.
Correct. A strong pre-test and post-test procedure should do more than authorize the test. It should confirm scope, rules of engagement, approved time windows, escalation paths, and protections against business disruption. It should also verify that backups are valid and restorable, and that logging and monitoring are tuned to observe test activity without creating confusion during incident response. Including explicit post-test success criteria, such as service validation, evidence preservation, exception handling, and ownership for confirming system integrity, addresses the common failure of receiving findings that cannot be efficiently validated. This is the most comprehensive and governance-aligned improvement.
- B. Incorrect.
Incorrect. A signed statement of work is necessary, but it is not sufficient. Dynamic coordination during a live penetration test increases the chance of scope misunderstandings, business outages, and delayed escalation when a critical issue occurs. Mature testing programs establish pre-test controls up front, especially for production-adjacent or production systems.
- C. Incorrect.
Incorrect. Executive approval is only one component of pre-test preparation. Deferring backup validation and monitoring readiness until after the test is a significant weakness because those controls are needed before testing starts. If disruption occurs and backups were not verified, recovery risk increases. If monitoring is not prepared in advance, the organization may miss key evidence or trigger unnecessary incident response actions.
- D. Incorrect.
Incorrect. Post-test procedures should not end with receipt of the report. Effective post-test activities include service health checks, review of tester actions against scope, validation of high-risk findings, preservation of logs and evidence, lessons learned, and coordinated remediation planning. Waiting passively for the final report delays containment of any issues uncovered during testing and weakens governance.