712-50 exam dumps

712-50 practice question 347 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 347

Single answerDevelop pre and post testing procedures

A newly appointed CISO is overseeing an external penetration test of the company's customer-facing applications and supporting infrastructure. The environment includes production systems that process online transactions, and the board has stated that business disruption during testing is unacceptable. Previous tests produced useful findings but also caused service instability because no formal pre-test or post-test procedure existed. Which action should the CISO take FIRST to establish effective pre- and post-testing procedures while balancing assurance needs and operational risk?

  1. A

    Require the penetration testing firm to begin with non-intrusive scanning and let the internal SOC decide during execution whether deeper testing is acceptable

  2. B

    Develop a formally approved test plan that defines scope, rules of engagement, authorized techniques, rollback and escalation paths, asset owners, evidence handling, and post-test validation and lessons learned activities

  3. C

    Instruct the operations team to create full backups before testing and defer all other planning activities until after the first test cycle identifies the riskiest systems

  4. D

    Limit the assessment to a vulnerability scan of internet-facing hosts so that pre-test and post-test procedures are not necessary

Show answer and explanation

Correct answer: B

Explanation

For a CISO, developing pre- and post-testing procedures is primarily a governance and risk management responsibility, not just a technical testing decision. The strongest first step is to implement a formally approved test plan and rules of engagement that define how testing will be conducted, how business risk will be controlled, and how the organization will verify system integrity afterward. In practice, pre-test procedures typically include written authorization, scope and asset identification, test objectives, stakeholder notification, maintenance windows, emergency stop conditions, communication paths, backup and rollback expectations, and logging or evidence requirements. Post-test procedures typically include system health checks, confirmation that no unauthorized changes persist, evidence retention, reporting, remediation ownership, and lessons learned. This approach is consistent with widely accepted security testing and governance practices reflected in standards and guidance such as NIST SP 800-115 on technical guide to security testing and assessment, which emphasizes planning, rules of engagement, and post-assessment activities, as well as broader control governance principles in frameworks like ISO/IEC 27001 and risk-based oversight expected of senior security leadership.

  • A. Incorrect.

    This is insufficient as the first action because it leaves key governance and risk controls undefined before testing begins. Starting with non-intrusive scanning may reduce immediate risk, but relying on the SOC to make ad hoc decisions during execution does not establish formal pre-test procedures such as documented scope, approvals, communication paths, business constraints, success criteria, stop conditions, or post-test restoration and verification steps. A mature security program requires these elements to be agreed in advance.

  • B. Correct.

    This is correct because the first priority is to establish a formal, approved testing procedure covering both pre-test and post-test activities. Pre-test controls should include scope definition, explicit authorization, system criticality, windows, communication channels, emergency contacts, allowed and prohibited methods, backup and rollback expectations, and criteria for suspending testing. Post-test procedures should include validation that systems remain stable, confirmation of restoration if changes occurred, evidence preservation, debriefing, root-cause and lessons-learned review, and remediation tracking. This approach aligns security assurance with business continuity and executive oversight.

  • C. Incorrect.

    Backups are important, but this option is too narrow and reactive to serve as the first action. It addresses one pre-test safeguard but ignores broader governance needs such as written authorization, rules of engagement, outage thresholds, test objectives, stakeholder notifications, and post-test verification. Deferring planning until after an initial test cycle exposes the organization to unnecessary operational and legal risk.

  • D. Incorrect.

    This is incorrect because reducing scope to scanning alone does not eliminate the need for pre-test and post-test procedures. Even vulnerability scanning can affect fragile systems, generate alerts, or require coordination with operations and monitoring teams. Moreover, the objective is to improve the testing program, not avoid governance by weakening the assessment. Proper procedures are still needed regardless of testing depth.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam