712-50 exam dumps

712-50 practice question 366 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 366

Single answerDiagnose and resolve IA problems in response to reported incidents

A global manufacturing company discovers that several engineers reported intermittent access denials to a product design repository, while at the same time the security operations center identifies successful logins to the same repository from a contractor account outside approved geographic regions. Initial investigation shows that a recent identity federation configuration change modified group-to-role mappings for the repository. As the CISO, you need to direct the response to diagnose and resolve the information assurance problem while minimizing business disruption and preserving evidence for further investigation. What is the BEST immediate action?

  1. A

    Disable the entire design repository until the identity team completes a full review of all federation settings

  2. B

    Revert the recent federation mapping change, preserve relevant authentication and access logs, and place the contractor account under targeted containment pending validation of authorized use

  3. C

    Force password resets for all repository users and notify engineering that access will remain limited until the quarterly IAM audit is completed

  4. D

    Remove all contractor access to the repository permanently and rebuild the identity provider trust relationship from scratch

Show answer and explanation

Correct answer: B

Explanation

The scenario combines two common incident-response challenges in information assurance: loss of availability for authorized users and potential unauthorized access caused by identity and access management misconfiguration. The best immediate action is to contain risk in a focused way, restore correct authorization by reversing the recent change, and preserve logs for investigation. This approach reflects established guidance from incident handling and access control best practices, including NIST SP 800-61 Rev. 2 for incident response lifecycle activities such as analysis, containment, eradication, and recovery, and NIST SP 800-53 controls related to access enforcement, audit logging, and configuration management. From a CCISO perspective, the decision balances security, operational continuity, and evidentiary integrity. Broad shutdowns or organization-wide resets may be appropriate in severe compromise scenarios, but here the most defensible executive response is targeted containment plus controlled rollback of the suspected faulty IAM change.

  • A. Incorrect.

    This is not the best immediate action because it prioritizes broad service shutdown over targeted incident response. While disabling the repository may reduce risk, it creates unnecessary operational disruption and does not directly address diagnosis of the suspected IAM misconfiguration and possible account misuse. Good incident handling practice favors proportionate containment and restoration of correct access while preserving evidence.

  • B. Correct.

    This is the best answer because it addresses both likely causes indicated by the scenario: an IAM configuration error affecting legitimate user access and suspicious account activity suggesting possible misuse. Reverting the known recent mapping change is a controlled way to restore authorized access. Preserving authentication and access logs supports forensic review and root-cause analysis. Targeted containment of the contractor account limits further risk without unnecessarily disrupting all users. This aligns with incident response best practices of containment, evidence preservation, eradication of the issue source, and business-aware recovery.

  • C. Incorrect.

    This is plausible because password resets are a common reaction to suspicious access, but it is not the best immediate action here. The reported symptoms strongly point to a federation authorization mapping issue, not solely an authentication compromise. A mass password reset would create significant disruption and may not resolve the improper role assignment. Waiting for a quarterly audit is also too slow for an active incident.

  • D. Incorrect.

    This option is overly destructive and not justified by the facts presented. Permanently removing all contractor access and rebuilding trust from scratch may be considered later if the trust relationship is proven compromised, but the current evidence indicates a recent mapping change is the most likely source of the IA problem. The response should be targeted, evidence-driven, and proportionate rather than irreversible and broad.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam