712-50 exam dumps

712-50 practice question 362 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 362

Single answerComply with system termination procedures and incident reporting requirements related to potential security incidents or actual breaches

A global company is decommissioning a legacy claims-processing server that contains customer PII and historical audit logs. During the approved shutdown window, the infrastructure team discovers outbound connections from the server to an unfamiliar external IP address and finds archived files staged in a temporary directory. The server is still connected to the corporate network, and the data retention schedule requires some records to be preserved for legal and regulatory purposes. As the CISO, what is the MOST appropriate next action to ensure compliance with both system termination procedures and incident reporting requirements?

  1. A

    Continue the decommissioning as planned, wipe the server immediately to eliminate risk, and document the anomaly after the asset is retired

  2. B

    Isolate the server from the network, preserve relevant logs and disk evidence, activate the incident reporting process, and coordinate termination steps with legal, compliance, and records management

  3. C

    Reboot the server into maintenance mode, allow the administrators to review the files, and wait for confirmation of data loss before escalating the event as an incident

  4. D

    Transfer the server image to a system administrator's workstation for faster analysis, then proceed with standard disposal once the suspicious files are deleted

Show answer and explanation

Correct answer: B

Explanation

The best answer is to isolate the affected system, preserve evidence, formally report the event, and coordinate decommissioning with legal, compliance, and records management stakeholders. In CCISO-level practice, system termination is not merely an IT shutdown task; it must align with information governance, legal hold requirements, asset disposal policy, and incident management processes. When suspicious activity is identified during decommissioning, the organization should transition from routine termination procedures to controlled incident handling. Relevant best practices include preserving potential evidence, maintaining chain of custody, avoiding actions that alter system state unnecessarily, and escalating according to the organization's incident response plan and breach notification decision process. This approach is consistent with common guidance from NIST incident handling and media sanitization practices, as well as ISO/IEC 27001 and 27002 controls related to asset management, event reporting, incident response, and secure disposal of information assets.

  • A. Incorrect.

    Incorrect. Immediate wiping destroys potential forensic evidence and may violate both incident response and records-retention obligations. When suspicious outbound activity and staged files are detected, the organization must treat the event as a potential security incident, preserve evidence, and follow formal reporting and escalation procedures before completing disposal or sanitization.

  • B. Correct.

    Correct. This response aligns with sound governance and incident handling practice: contain the asset by isolating it, preserve logs and system state for investigation, initiate formal incident reporting, and ensure decommissioning does not conflict with legal hold, retention, or regulatory obligations. It also reflects proper separation between incident response activities and end-of-life asset disposal procedures.

  • C. Incorrect.

    Incorrect. Rebooting can alter volatile evidence, timestamps, processes, and connections, reducing the integrity of the investigation. Waiting for proof of confirmed data loss is also a mistake; incident reporting requirements generally apply to suspected incidents and potential breaches, not only confirmed exfiltration events.

  • D. Incorrect.

    Incorrect. Moving the image to an administrator's workstation can break chain-of-custody controls and expose evidence to unauthorized handling. Deleting suspicious files before investigation also compromises evidence preservation. Standard disposal should not resume until incident response, legal review, and retention requirements are addressed.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam