712-50 exam dumps

712-50 practice question 360 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 360

Single answerDevelop a plan to identify a potential security violation and take appropriate action to report the incident

A newly appointed CISO is formalizing the organization’s approach to identifying potential security violations and ensuring incidents are reported appropriately. During a recent event, an engineer noticed unusual outbound traffic from a finance server, but the activity was not escalated for several hours because staff were unsure whether it was a policy exception, a technical fault, or a reportable security incident. The board has asked for a plan that improves early identification and consistent reporting without creating unnecessary false alarms. Which action should the CISO prioritize FIRST to build an effective and defensible incident reporting process?

  1. A

    Define incident classification criteria, reporting thresholds, escalation paths, and evidence-handling requirements in a formal incident response and reporting procedure, then train staff on how to use it

  2. B

    Require all suspicious technical events to be reported directly to the board so leadership can determine whether they are true security incidents

  3. C

    Delay formal reporting procedures until the security operations team finishes deploying more advanced monitoring tools to reduce false positives

  4. D

    Instruct system administrators to contain unusual activity immediately and document the event afterward if it appears serious

Show answer and explanation

Correct answer: A

Explanation

This question tests a core CCISO responsibility: designing governance-driven incident identification and reporting processes that enable timely, consistent action across the enterprise. The best first action is to define and institutionalize criteria for identifying potential security violations, reporting thresholds, escalation paths, and evidence-handling expectations. In practice, this is typically implemented through an incident response policy, supporting procedures, and role-based training. This aligns with widely accepted guidance such as NIST SP 800-61 Rev. 2, which emphasizes establishing incident definitions, reporting mechanisms, triage, and escalation; ISO/IEC 27035, which focuses on incident management processes; and ISO/IEC 27001 controls related to information security incident management and reporting. From a CISO perspective, the priority is not just technical detection but creating a repeatable, auditable process that staff can follow under uncertainty. A defensible plan ensures potential violations are recognized early, routed correctly, investigated consistently, and reported to management, legal, HR, regulators, or law enforcement as appropriate.

  • A. Correct.

    Correct. The most effective first step is to establish a formal, organization-wide process that defines what constitutes a potential security violation, how to distinguish events from incidents, when personnel must report, who receives reports, how escalation works, and how evidence must be preserved. This directly addresses the root cause in the scenario: uncertainty about whether and how to report. Training is essential because even strong procedures fail if users and administrators do not understand their responsibilities.

  • B. Incorrect.

    Incorrect. Board oversight is important, but routing all suspicious events directly to the board is operationally inefficient and inconsistent with normal governance structures. The board should receive material incident reporting and metrics, not act as the first-line triage function. This option reflects a common misconception that executive visibility should replace operational incident handling.

  • C. Incorrect.

    Incorrect. Better monitoring can improve detection, but delaying formal reporting procedures leaves the organization exposed to the same decision-making gap described in the scenario. Mature security programs define reporting and escalation processes independently of tooling maturity. Tools support the process; they do not replace governance, classification, or accountability.

  • D. Incorrect.

    Incorrect. Immediate containment can be appropriate in some cases, but instructing administrators to act first and document later creates legal, forensic, and governance risk. Without predefined criteria and reporting requirements, staff may destroy evidence, fail to notify the right stakeholders, or take inconsistent actions. This option reflects the common error of prioritizing ad hoc technical response over controlled incident management.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam