712-50 exam dumps

712-50 practice question 349 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 349

Single answerDevelop a plan for pen test reporting and implementation of technical vulnerability corrections

A newly appointed CISO receives the results of an external penetration test that identified several exploitable weaknesses, including an internet-facing application flaw that allowed unauthorized access to customer records in a test environment and multiple high-severity unpatched systems in the DMZ. The board wants an executive summary within 48 hours, while infrastructure and application owners need actionable remediation guidance. The organization has previously struggled because pen test findings were sent as a single technical report, with no ownership, no retest plan, and no linkage to risk treatment decisions. Which action should the CISO take FIRST to develop an effective pen test reporting and remediation implementation plan?

  1. A

    Distribute the full penetration test report to all IT staff immediately and require every finding to be remediated within 30 days, regardless of business criticality

  2. B

    Create a tiered reporting approach that separates executive risk reporting from technical remediation details, assigns owners and due dates based on risk, defines compensating controls where immediate fixes are not possible, and includes validation/retesting requirements

  3. C

    Delay reporting until the security team independently verifies every finding and fully develops technical fixes, so leadership receives only confirmed and closed issues

  4. D

    Focus initial reporting on the penetration tester's exploit methods and tools so internal teams can reproduce each attack path before prioritizing remediation

Show answer and explanation

Correct answer: B

Explanation

The best first action is to establish a structured remediation governance process tied to risk-based reporting. In practice, penetration test outputs should be translated into at least two audiences: executive stakeholders who need business impact, risk exposure, and decisions required; and technical owners who need specific remediation steps, affected assets, evidence, and retest criteria. A strong plan includes severity and business-context prioritization, clearly assigned owners, target dates, exception handling, compensating controls, and closure validation. This approach aligns with common security program practices reflected in NIST vulnerability management and risk response concepts, such as NIST SP 800-40 for enterprise patch and vulnerability management, NIST SP 800-61 for coordinated handling of significant security issues, and NIST SP 800-53 controls such as RA-5 (Vulnerability Monitoring and Scanning), SI-2 (Flaw Remediation), and CA-8 (Penetration Testing). From a CCISO perspective, the key competency is not merely understanding test results, but ensuring they are reported appropriately, converted into accountable corrective actions, and validated through retesting or other evidence-based closure processes.

  • A. Incorrect.

    This is incorrect because broad distribution of a full technical report to all IT staff violates the principle of need-to-know and often reduces accountability. Requiring uniform remediation timelines regardless of asset criticality, exploitability, or business impact is not risk-based and can misallocate resources. Effective CISO-level governance requires prioritization, ownership, and formal tracking rather than mass distribution and arbitrary deadlines.

  • B. Correct.

    This is correct because it addresses both reporting and implementation in a structured, risk-based way. Executives need concise business-impact reporting, while system owners need detailed technical guidance. Assigning owners, due dates, and remediation paths creates accountability. Including compensating controls supports risk treatment when immediate correction is not feasible. Requiring validation or retesting ensures that fixes are effective and that findings are not simply marked closed without evidence. This reflects mature vulnerability management and remediation governance.

  • C. Incorrect.

    This is incorrect because leadership should be informed promptly of material risk, especially when customer data exposure is implicated. Waiting until every finding is independently verified and fully remediated delays risk communication and undermines timely decision-making. Verification is important, but not at the expense of escalation, interim controls, and risk ownership.

  • D. Incorrect.

    This is incorrect because reproducing exploit techniques can help technical teams understand findings, but it should not be the primary focus of initial reporting. The CISO's first priority is to translate the test results into business risk, ownership, remediation actions, and tracking. Excessive focus on attacker tooling can distract from governance, prioritization, and corrective action planning.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam