712-50 exam dumps

712-50 practice question 363 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 363

Single answerComply with system termination procedures and incident reporting requirements related to potential security incidents or actual breaches

A global enterprise is decommissioning a legacy customer relationship management (CRM) server that contains personally identifiable information and historical support records. During the shutdown window, an engineer discovers outbound connections from the server to an unfamiliar external IP address and notices that the standard data sanitization checklist has not yet been completed. Business leaders are pressuring the team to power off and dispose of the server immediately to meet a datacenter exit deadline. As the CISO, what is the MOST appropriate action to ensure compliance with both system termination procedures and incident reporting requirements?

  1. A

    Proceed with immediate shutdown and disposal to prevent further outbound traffic, then review logs later if needed

  2. B

    Delay decommissioning, preserve the system and relevant logs as potential evidence, activate incident reporting and escalation procedures, and resume termination only after authorized investigation steps are completed

  3. C

    Disconnect the server from the network, allow operations to finish wiping the disks, and report the event at the next scheduled risk committee meeting

  4. D

    Have the engineer capture screenshots of the suspicious connections, then complete the disposal process because the server was already approved for retirement

Show answer and explanation

Correct answer: B

Explanation

When a system scheduled for retirement shows signs of possible compromise, the organization must follow both decommissioning controls and incident response obligations. From a governance perspective, termination procedures typically require documented asset inventory updates, approved change records, media sanitization, evidence of data retention decisions, and secure disposal. However, these steps must be suspended if they would destroy evidence relevant to a suspected incident or breach. Best practice is to contain appropriately, preserve volatile and non-volatile evidence where feasible, retain logs, document actions taken, and trigger the organization's incident reporting and escalation workflow immediately. This aligns with widely accepted guidance such as NIST SP 800-61 for incident handling, which emphasizes evidence preservation and timely reporting, and NIST SP 800-88 for media sanitization, which assumes sanitization occurs in a controlled and authorized manner. For CISO-level decision-making, the key is balancing operational urgency with regulatory, legal, forensic, and governance requirements so the organization does not lose evidence or fail to meet breach assessment and reporting obligations.

  • A. Incorrect.

    This is incorrect because immediate disposal can destroy potential forensic evidence and may violate both incident response obligations and formal media sanitization/asset disposition procedures. While containing outbound traffic is important, proper containment should be balanced with evidence preservation, chain of custody, and timely reporting under the organization's incident management process.

  • B. Correct.

    This is correct because suspected malicious outbound communication on a system containing sensitive data must be treated as a potential security incident. The appropriate executive action is to pause termination activities, preserve the asset and relevant logs, initiate the organization's incident reporting and escalation process, and coordinate with legal, privacy, and forensic stakeholders as required. Decommissioning should continue only after the investigation confirms that evidence has been preserved and approved termination steps can safely proceed.

  • C. Incorrect.

    This is incorrect because although network isolation may be a valid containment measure, allowing disk wiping to continue before investigative preservation is complete can eliminate critical evidence. In addition, deferring notification until the next risk committee meeting is too slow for a potential breach and does not meet normal incident reporting timeliness requirements.

  • D. Incorrect.

    This is incorrect because screenshots are not a sufficient substitute for full evidence preservation, such as system images, log retention, and documented chain of custody where required. The fact that the server was approved for retirement does not override incident reporting, potential breach assessment, or formal termination controls for systems containing regulated or sensitive information.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam