712-50 exam dumps

712-50 practice question 348 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 348

Single answerDevelop a plan for pen test reporting and implementation of technical vulnerability corrections

A newly appointed CISO receives the final report from an external penetration test covering internet-facing applications, internal network segments, and privileged access pathways. The report identifies several critical findings, including an exploitable remote code execution flaw on a public web server, excessive Active Directory privileges, and unsupported systems in a business-critical manufacturing environment. The CEO wants immediate remediation, while the operations team warns that uncoordinated fixes could disrupt production. The board has also asked for a clear status update within 30 days. Which action should the CISO take FIRST to create an effective pen test reporting and remediation implementation plan?

  1. A

    Direct technical teams to remediate every finding in the order listed in the penetration test report and provide the board with the full raw report for transparency

  2. B

    Establish a risk-based remediation plan that validates findings, assigns business owners and technical owners, prioritizes by exploitability and business impact, defines target dates and compensating controls, and creates executive and technical reporting tracks

  3. C

    Ask the penetration testing firm to retest immediately before any remediation work begins so leadership can confirm the findings are severe enough to justify operational disruption

  4. D

    Defer remediation of all findings affecting unsupported systems until the next annual technology refresh cycle because those assets are already known technical debt

Show answer and explanation

Correct answer: B

Explanation

In a CCISO context, the CISO's role is not merely to receive a penetration test report but to convert it into an enterprise remediation program aligned to risk management, business operations, and executive governance. The best first step is to establish a risk-based remediation plan with ownership, prioritization, due dates, exception handling, and reporting tailored to different audiences. This approach reflects common best practices from sources such as NIST SP 800-40 for enterprise patch and vulnerability management, NIST SP 800-61 for coordinated response activities, and the CVSS framework as one input to severity assessment. However, severity scores alone are insufficient; effective prioritization also considers asset value, exposure, exploitability, business impact, operational constraints, and compensating controls. Executive reporting should summarize business risk, remediation status, blockers, and decisions required, while technical teams need actionable details for correction and validation. This structure enables timely fixes for critical issues, controlled handling of production risks, and defensible communication to the board.

  • A. Incorrect.

    This is incorrect because remediation should not simply follow the report's listing order. Penetration test reports are not necessarily ordered according to the organization's business priorities, operational constraints, or risk appetite. Sending the full raw report to the board is also poor practice; boards typically need a concise risk-focused summary, not exploit details that are operationally sensitive and not decision-oriented. A mature CISO function translates technical findings into risk, ownership, timelines, and governance reporting.

  • B. Correct.

    This is correct because the first priority is to operationalize the pen test results into a governance-driven remediation plan. That includes validating findings, mapping them to assets and business processes, assigning accountable business owners and responsible technical owners, prioritizing based on risk factors such as exploitability, exposure, privilege implications, and business criticality, and defining deadlines, exceptions, and compensating controls where immediate remediation is not feasible. Separate reporting tracks are also appropriate: detailed technical remediation guidance for operations teams and an executive summary for senior leadership and the board.

  • C. Incorrect.

    This is incorrect because retesting before remediation delays risk reduction and misunderstands the purpose of validation. If there are questions about false positives or exploit conditions, targeted validation can occur as part of triage, but a full retest should generally follow remediation of high-priority findings to verify closure. The misconception here is treating retesting as a prerequisite for action rather than a verification step in the remediation lifecycle.

  • D. Incorrect.

    This is incorrect because unsupported systems in critical environments often present elevated risk and require immediate treatment planning, not automatic deferral. While replacing legacy systems may take time, the CISO should ensure compensating controls, segmentation, access restrictions, monitoring, virtual patching where feasible, and formal risk acceptance if residual risk remains. Deferral without documented risk treatment and governance is not an effective remediation strategy.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam