712-50 exam dumps

712-50 practice question 36 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 36

Single answer

A global insurance company deploys a third-party AI model to prioritize fraudulent claims for investigator review. Six weeks after launch, regulators ask how the model’s decisions can be explained, while internal audit finds that claimants from one region are being flagged at a much higher rate than peers with similar loss patterns. At the same time, the security team warns that analysts have been pasting full claim files, including personal data, into the vendor’s hosted prompt interface to get faster summaries. As the CISO, which action should you recommend FIRST to reduce the most immediate enterprise risk while supporting compliance and trustworthy AI use?

  1. A

    Suspend the use of full production claim data in the hosted AI interface, require approved data-handling controls and privacy review, and move to sanitized or minimized inputs until governance controls are in place

  2. B

    Keep the deployment unchanged but ask the vendor for a marketing whitepaper describing the model architecture and training approach

  3. C

    Increase the fraud score threshold globally so fewer claims are flagged while the team investigates the regional disparity

  4. D

    Require investigators to manually review only the claims from the affected region so the organization can continue using the model elsewhere

Show answer and explanation

Correct answer: A

Explanation

The scenario includes several AI risk categories: bias or disparate impact (one region flagged at a higher rate), limited model transparency or explainability (regulators want decision rationale), inaccuracies or poor calibration (implied by unexplained differential outcomes), data security/privacy risk (staff entering full claim files into a hosted service), and possible third-party/model governance weaknesses. For a CCISO, the FIRST recommendation should focus on the highest-immediacy enterprise risk with clear legal and security consequences: uncontrolled sensitive data exposure. Data entered into externally hosted AI tools can create confidentiality, privacy, retention, residency, and contractual risks unless governed by approved controls.

This approach aligns with widely recognized guidance such as the NIST AI Risk Management Framework (govern, map, measure, manage), which emphasizes managing privacy, security, transparency, and harmful bias together; the NIST Secure Software Development Framework and broader secure-by-design principles for integrating third-party technologies; and common privacy principles such as data minimization and purpose limitation found in major regulatory regimes. After immediate containment of data handling risk, the organization should perform a structured review of model performance, fairness testing across relevant cohorts, documentation of intended use and limitations, and third-party assurance for explainability, security, and contractual controls.

  • A. Correct.

    Correct. This addresses the most immediate and concrete risk: potential unauthorized disclosure or misuse of personal data through a hosted AI service. From a CISO perspective, data security and privacy exposure typically require immediate containment because they may create regulatory, contractual, and breach-notification consequences. Requiring data minimization, approved use patterns, and privacy/legal review is consistent with established security governance and AI risk management practices. It also creates space to investigate the bias and explainability issues without continuing unsafe handling of sensitive data.

  • B. Incorrect.

    Incorrect. Vendor documentation may help with transparency, but a marketing whitepaper is not a sufficient control and does not mitigate the immediate exposure created by analysts entering personal claim data into a hosted interface. It also does not directly address the discovered disparate impact. This option reflects a common mistake of treating documentation as a substitute for risk treatment.

  • C. Incorrect.

    Incorrect. Raising the threshold may reduce alert volume, but it does not solve the root issues of possible bias, weak explainability, or insecure data handling. It can also degrade fraud detection performance and create unmeasured business impact. This is a tuning change without governance or assurance evidence.

  • D. Incorrect.

    Incorrect. Segregating one region for manual review may appear responsive to the fairness concern, but it does not address the primary near-term security and privacy risk of analysts submitting sensitive data to an external AI service. It may also introduce inconsistent operating practices and potential discrimination concerns if not supported by a formal risk assessment.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam